Androidauthority Google Chrome Enhances Security with Device Bound Session Credentials
Article Content
- •DBSC binds session cookies to the device, enhancing security against theft.
- •The feature is enabled by default for all users, including Google Workspace customers.
- •Rollout began on May 25, 2026, and will complete within 60 days.
Google has rolled out its Device Bound Session Credentials (DBSC) feature for Chrome, aimed at preventing session cookie theft. This feature cryptographically binds session cookies to the user's device, making it significantly harder for attackers to exploit stolen cookies. Initially available in beta, DBSC is now enabled by default for all Google Workspace and personal account users on Windows. The rollout began on May 25, 2026, and is expected to complete within 60 days. This enhancement addresses past vulnerabilities where attackers could exploit stolen cookies to bypass multi-factor authentication. Google has previously warned users about malware that could restore expired authentication cookies, emphasizing the importance of this new feature. The DBSC implementation is a proactive measure to enhance account security against session hijacking threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track The Gentlemen and Lumma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…
Multiple Ransomware Attacks Target Diverse Industries in September 2026 In early September 2026, several ransomware groups executed attacks on various organizations, including Krybit's assault on Reignwood Park Thailand and Arab Maritime Petroleum Transport Company, Everest's attack on VIVOTEK, and Settra's targeting of Golden Neo Life. These incidents involved threats to leak sensitive…