logo

Infostealer malware bypasses Chrome’s new cookie-theft defenses

ID: 5c6e2e32-cd18-5a3a-bd9e-8f39d74025cf

STIX ID: report--5c6e2e32-cd18-5a3a-bd9e-8f39d74025cf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple infostealer malware families (Lumma, Whitesnake, Vidar, Meduza, StealC, Lumar) have publicly claimed — and researchers have in some cases validated — methods to bypass Chrome's App-Bound Encryption (introduced in Chrome 127+) to extract cookies and stored credentials; some variants reportedly do so without needing administrative privileges, and researchers demonstrated cookie extraction from recent Chrome versions in sandbox tests, prompting acknowledgement from Google and highlighting a shift by attackers toward injection or memory-scraping techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.