Google Chrome’s Device-Bound Session Credentials Now GA to Block Account Takeovers
ID: 50ae6267-d79c-57ac-8290-2a34a0154803
STIX ID: report--50ae6267-d79c-57ac-8290-2a34a0154803
Feed Name: cybersecurityNews.com
Google has made Device Bound Session Credentials (DBSC) generally available in Chrome on Windows, enabling session cookies to be cryptographically bound to the device that authenticated them. The feature, enabled by default and integrated with Context-Aware Access, aims to mitigate pass-the-cookie attacks by rendering exfiltrated cookies unusable on other machines; admins can view DBSC binding events in audit logs and are advised to baseline and monitor this activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
