Google Chrome Implements Device Bound Session Credentials to Combat Cookie Theft

Google Chrome Implements Device Bound Session Credentials to Combat Cookie Theft

First seen 9 Apr 2026, 19:01 UTC Feeds.FeedburnerBleepingcomputerFeeds2.FeedburnerInfosecurity-MagazineScworld+4 87% similarity 67.5

Article Content

Browse articles
ThreatCluster

Google has launched Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aimed at preventing session cookie theft by infostealer malware. This security feature, which will extend to macOS in a future release, cryptographically binds session cookies to specific hardware, utilizing security chips like the Trusted Platform Module (TPM) and Secure Enclave. By generating unique public/private key pairs that cannot be exported, DBSC ensures that any exfiltrated session cookies quickly expire, rendering them useless to attackers. The DBSC protocol was developed in collaboration with Microsoft and tested with various web platforms, showing a notable decline in session theft incidents. Infostealer malware, such as LummaC2, has become increasingly sophisticated in harvesting session cookies, allowing unauthorized access to user accounts without passwords. The proactive nature of DBSC marks a significant shift from traditional reactive security measures. Google emphasizes that this approach mitigates the risks associated with session theft more effectively than previous methods.

Key Points: • DBSC protects session cookies by binding them to specific hardware, preventing theft. • Infostealer malware like LummaC2 exploits session cookies to access accounts without passwords. • The protocol has shown a decline in session theft incidents during its testing phase.

ThreatCluster AI

Timeline

2024-04-01
Google announces Device Bound Session Credentials (DBSC) project
2026-04-09
DBSC protection launched in Chrome 146 for Windows
Date unknown
DBSC feature to be available for macOS in future release

Community

Browse all →