Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
ID: 07496b79-2909-5aaf-8c5f-c47677911d27
STIX ID: report--07496b79-2909-5aaf-8c5f-c47677911d27
Feed Name: The Hacker News
Threat Score
Google has made Device Bound Session Credentials (DBSC) generally available to Windows users in Chrome 146 to reduce session theft by tying short-lived session cookies to hardware-backed keys (e.g., TPM/Secure Enclave). The feature aims to render exfiltrated cookies useless to stealers (such as Atomic, Lumma, and Vidar) while providing fallbacks for devices without secure key storage and maintaining privacy by design.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
