logo

Hardware-Locked: How Chrome’s New DBSC Makes Stolen Cookies Worthless

ID: ef691468-1414-56c1-8400-9428acba1c50

STIX ID: report--ef691468-1414-56c1-8400-9428acba1c50

Feed Name: securityonline.info

Threat Score
30/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Google has made Device Bound Session Credentials (DBSC) publicly available starting with Chrome 146 on Windows; DBSC cryptographically binds session credentials to a device's secure hardware (TPM/Secure Enclave) so exfiltrated session cookies are unusable on other machines, aiming to mitigate session hijacking by infostealers such as LummaC2 while preserving privacy via per-session keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.