Google Rolls Out DBSC in Chrome to Prevent Session-Based Account Takeovers
ID: 2dcc7905-248d-5868-a959-a1fb77b4c7d3
STIX ID: report--2dcc7905-248d-5868-a959-a1fb77b4c7d3
Feed Name: Cyber Press
Google has moved Device-Bound Session Credentials (DBSC) to general availability in Chrome for Windows, enabling cryptographic binding of session cookies to a device's secure hardware (TPM) so stolen cookies are unusable on other devices. The rollout, enabled by default for Workspace and personal accounts and integrated with Context-Aware Access and audit logs, is presented as a mitigation against session-hijacking and cookie-theft attacks that can bypass MFA; the announcement notes the gradual rollout began May 25, 2026 and requires no admin or end-user configuration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
