logo

Google Chrome adds session cookie theft protection for all users

ID: 499fe8c2-d16b-5c37-ba04-04c2100cbd3a

STIX ID: report--499fe8c2-d16b-5c37-ba04-04c2100cbd3a

Feed Name: Bleeping Computer

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Sergiu Gatlan

...
...

Google has begun rolling out Chrome Device Bound Session Credentials (DBSC), a feature that cryptographically binds session cookies to device hardware (e.g., TPM on Windows, Secure Enclave on macOS) so stolen cookies cannot be reused to bypass MFA and hijack accounts; the feature is enabled by default for Workspace customers and widely available to users. The article notes prior abuses—undocumented OAuth MultiLogin endpoint misuse and claims by info-stealers like Lumma and Rhadamanthys—to explain the mitigation's importance, but it is an announcement of a security control rather than a report of an active incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.