logo

New Chrome feature aims to stop hackers from using stolen cookies

ID: 91fdac7a-dee3-53de-9a31-528b7f193eb4

STIX ID: report--91fdac7a-dee3-53de-9a31-528b7f193eb4

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-04-02

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Google is developing Device Bound Session Credentials (DBSC) for Chromium-based browsers to cryptographically bind authentication cookies to TPM-backed device keys, preventing stolen cookies from being reused to hijack accounts; the report notes that infostealer malware and operators such as Lumma and Rhadamanthys have been abusing an undocumented Google OAuth endpoint to revive or reuse stolen cookies, and that DBSC — currently prototype/testable via chrome://flags — aims to neutralize that attack vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.