Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move
ID: a517ad74-1520-5b14-9494-44b067814dd5
STIX ID: report--a517ad74-1520-5b14-9494-44b067814dd5
Feed Name: cybersecurityNews.com
Google announced the public rollout of Device Bound Session Credentials (DBSC) for Windows in Chrome 146, a hardware-backed mechanism (TPM/Secure Enclave) that ties authentication sessions to a device-specific private key to prevent session hijacking via stolen cookies. The article outlines how DBSC mitigates the threat of cookie exfiltration by infostealing malware (e.g., LummaC2), describes privacy protections and cross-vendor development, and notes planned expansion to macOS and enterprise SSO scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
