Google Locks Chrome Sessions to Devices to Stop Cookie Theft
ID: feb6471f-c2cc-5327-a723-91e8d2234db9
STIX ID: report--feb6471f-c2cc-5327-a723-91e8d2234db9
Feed Name: GBHackers
Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to prevent session hijacking by cryptographically binding short-lived session cookies to hardware-backed keys (TPM on Windows, with macOS support coming). The feature aims to stop infostealer-style attacks (the report mentions LummaC2) from reusing stolen cookies, emphasizes privacy protections and W3C standardization, and outlines future expansions for enterprise SSO and software-based keys for older devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
