logo

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

ID: 07496b79-2909-5aaf-8c5f-c47677911d27

STIX ID: report--07496b79-2909-5aaf-8c5f-c47677911d27

Feed Name: The Hacker News

Threat Score
30/100

Date Published: 2026-04-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google has made Device Bound Session Credentials (DBSC) generally available to Windows users in Chrome 146 to reduce session theft by tying short-lived session cookies to hardware-backed keys (e.g., TPM/Secure Enclave). The feature aims to render exfiltrated cookies useless to stealers (such as Atomic, Lumma, and Vidar) while providing fallbacks for devices without secure key storage and maintaining privacy by design.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.