logo

New tool bypasses Google Chrome’s new cookie encryption system

ID: c6fc982e-790a-59ef-833c-6f7e643e78c1

STIX ID: report--c6fc982e-790a-59ef-833c-6f7e643e78c1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A researcher published a GitHub tool called "Chrome-App-Bound-Encryption-Decryption" that leverages Chrome's IElevator COM interface to decrypt App-Bound encrypted keys stored in Chrome's Local State file, enabling extraction of cookies and possibly stored credentials/payment data; while the tool requires administrator privileges to place the executable in Chrome's install directory, security analysts warn its public release lowers the bar for infostealer operations and increases the risk of credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.