Google Chrome Enhances Security with Device Bound Session Credentials

Google Chrome Enhances Security with Device Bound Session Credentials

First seen 29 May 2026, 17:14 UTC BleepingcomputerAndroidauthorityCybersecuritynewsGbhackersZdnet+3 88% similarity 30.9

Article Content

Browse articles
ThreatCluster

Google has rolled out its Device Bound Session Credentials (DBSC) feature for Chrome, aimed at preventing session cookie theft. This feature cryptographically binds session cookies to the user's device, making it significantly harder for attackers to exploit stolen cookies. Initially available in beta, DBSC is now enabled by default for all Google Workspace and personal account users on Windows. The rollout began on May 25, 2026, and is expected to complete within 60 days. This enhancement addresses past vulnerabilities where attackers could exploit stolen cookies to bypass multi-factor authentication. Google has previously warned users about malware that could restore expired authentication cookies, emphasizing the importance of this new feature. The DBSC implementation is a proactive measure to enhance account security against session hijacking threats.

Key Points: • DBSC binds session cookies to the device, enhancing security against theft. • The feature is enabled by default for all users, including Google Workspace customers. • Rollout began on May 25, 2026, and will complete within 60 days.

ThreatCluster AI

Timeline

2024-01-01
DBSC announced
Google first announced the Device Bound Session Credentials feature as a security enhancement for Chrome.
BleepingComputer
2026-04-01
DBSC enters beta testing
The DBSC feature was made available in beta for select users, focusing on improving session security.
BleepingComputer
2026-05-25
DBSC rollout begins
Google started the general rollout of the DBSC feature to all users, enhancing Chrome's security.
AndroidAuthority
2026-05-30
DBSC officially available
Google confirmed that DBSC is now generally available, providing robust protection against session hijacking.
Cybersecuritynews

Community

Browse all →