New Chrome feature aims to stop hackers from using stolen cookies
ID: 91fdac7a-dee3-53de-9a31-528b7f193eb4
STIX ID: report--91fdac7a-dee3-53de-9a31-528b7f193eb4
Feed Name: Bleeping Computer
Google is developing Device Bound Session Credentials (DBSC) for Chromium-based browsers to cryptographically bind authentication cookies to TPM-backed device keys, preventing stolen cookies from being reused to hijack accounts; the report notes that infostealer malware and operators such as Lumma and Rhadamanthys have been abusing an undocumented Google OAuth endpoint to revive or reuse stolen cookies, and that DBSC — currently prototype/testable via chrome://flags — aims to neutralize that attack vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
