New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation
ID: 61822c8a-53af-59fd-817c-143c4ff03319
STIX ID: report--61822c8a-53af-59fd-817c-143c4ff03319
Feed Name: cybersecurityNews.com
Threat Score
A new VoidStealer v2.0 variant (first seen March 13, 2026) uses a debugger-based technique to bypass Chrome's Application-Bound Encryption (ABE) without injecting code or needing SYSTEM privileges, by setting hardware breakpoints to capture the transient plaintext v20_master_key from browser memory; it is distributed as Malware-as-a-Service, targets Chrome and Edge, and includes a provided IOC hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
