logo

Google Chrome gets ‘Device Bound Session Credentials’ to stop cookie theft

ID: d9ff6c49-9f2e-57fd-bbb7-3146eac30951

STIX ID: report--d9ff6c49-9f2e-57fd-bbb7-3146eac30951

Feed Name: Malwarebytes Blog

Date Published: 2024-04-03

Date Updated: 2026-04-28

...
...

Google announced Device Bound Session Credentials (DBSC) to protect Chrome users from cookie theft by info-stealer malware, binding authentication cookies to device-resident private keys so stolen cookies are unusable; the approach is intended to force attackers to operate locally and enhance on-device detection, aligns with Google’s move away from third-party cookies, is being developed openly toward a 2024 trial, and has interest from identity providers and other browsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.