logo

Google Locks Chrome Sessions to Devices to Stop Cookie Theft

ID: feb6471f-c2cc-5327-a723-91e8d2234db9

STIX ID: report--feb6471f-c2cc-5327-a723-91e8d2234db9

Feed Name: GBHackers

Date Published: 2026-04-11

Date Updated: 2026-04-22

Author: Divya

...
...

Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to prevent session hijacking by cryptographically binding short-lived session cookies to hardware-backed keys (TPM on Windows, with macOS support coming). The feature aims to stop infostealer-style attacks (the report mentions LummaC2) from reusing stolen cookies, emphasizes privacy protections and W3C standardization, and outlines future expansions for enterprise SSO and software-based keys for older devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.