Google Chrome’s New Feature Takes Aim at Cookie Theft, Account Hijacking
ID: 705a8384-7778-528b-b101-78d730c3de3a
STIX ID: report--705a8384-7778-528b-b101-78d730c3de3a
Feed Name: TechRepublic Security
Google is rolling out Device Bound Session Credentials (DBSC) for Chrome to cryptographically bind session cookies to device hardware (using TPM on Windows and Secure Enclave on macOS), making stolen cookies much harder for attackers to reuse; the feature began rolling out in May, requires recent Chrome versions (Windows 146+, macOS 148+) and hardware support, cannot be turned off, and aims to reduce session-cookie-based account takeovers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
