logo

To counter cookie theft, Chrome ships device-bound session credentials

ID: e27a9850-0140-51f7-8a8c-08fd6cb2d67a

STIX ID: report--e27a9850-0140-51f7-8a8c-08fd6cb2d67a

Feed Name: Help Net Security

Date Published: 2026-04-10

Date Updated: 2026-04-28

Author: Mirko Zorz

...
...

This article explains Google's Device Bound Session Credentials (DBSC), a W3C-standard protocol that cryptographically binds web session cookies to device-specific hardware-backed keys (TPM on Windows, Secure Enclave on macOS) to prevent cookie theft and unauthorized session renewal. It covers how DBSC works, its privacy properties, industry collaboration and origin trials, observed reductions in session theft at Google, and planned enhancements for federated identity, advanced registration, and broader device support.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.