Androidauthority
Google Chrome Enhances Security with Device Bound Session Credentials
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Google has rolled out its Device Bound Session Credentials (DBSC) feature for Chrome, aimed at preventing session cookie theft. This feature cryptographically binds session cookies to the user's device, making it significantly harder for attackers to exploit stolen cookies. Initially available in beta, DBSC is now enabled by default for all Google Workspace and personal account users on Windows. The rollout began on May 25, 2026, and is expected to complete within 60 days. This enhancement addresses past vulnerabilities where attackers could exploit stolen cookies to bypass multi-factor authentication. Google has previously warned users about malware that could restore expired authentication cookies, emphasizing the importance of this new feature. The DBSC implementation is a proactive measure to enhance account security against session hijacking threats.
Key Points: • DBSC binds session cookies to the device, enhancing security against theft. • The feature is enabled by default for all users, including Google Workspace customers. • Rollout began on May 25, 2026, and will complete within 60 days.