Google Chrome’s DBSC Now Generally Available to Prevent Account Takeovers
ID: eb4adef4-a786-524d-9ec9-3e9b5930dd7e
STIX ID: report--eb4adef4-a786-524d-9ec9-3e9b5930dd7e
Feed Name: GBHackers
Google has made Device Bound Session Credentials (DBSC) generally available in Chrome on Windows, binding session cookies to the physical device to prevent session cookie theft and pass-the-cookie attacks. The rollout began May 25, 2026 and applies by default to all Workspace tiers, Workspace Individual, and personal Google accounts; DBSC integrates with Context-Aware Access and logs binding events for security investigations, and administrators do not need to enable it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
