Hardware-Locked: How Chrome’s New DBSC Makes Stolen Cookies Worthless
ID: ef691468-1414-56c1-8400-9428acba1c50
STIX ID: report--ef691468-1414-56c1-8400-9428acba1c50
Feed Name: securityonline.info
Threat Score
Google has made Device Bound Session Credentials (DBSC) publicly available starting with Chrome 146 on Windows; DBSC cryptographically binds session credentials to a device's secure hardware (TPM/Secure Enclave) so exfiltrated session cookies are unusable on other machines, aiming to mitigate session hijacking by infostealers such as LummaC2 while preserving privacy via per-session keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
