New CDP Attack Targets Live Browser Sessions on Windows

New CDP Attack Targets Live Browser Sessions on Windows

First seen 17 Aug 2026, 13:47 UTC ThehackernewsFeeds.4Sysops 74% similarity 64.5

Article Content

Browse articles
ThreatCluster

A recently disclosed post-exploitation technique allows attackers to hijack live sessions in Google Chrome and Microsoft Edge after compromising Windows systems. This method leverages the Chrome DevTools Protocol (CDP) to access authenticated sessions without needing to steal cookies. The attack requires prior code execution on the victim's machine, making it particularly dangerous for users with active browser sessions. Affected users include anyone running these browsers on compromised Windows systems. The technique exposes sensitive data, including browser activity, WebAuthn interactions, and extensions, while bypassing existing protections against cookie theft. The full scope of the attack's impact is still being assessed, but it poses a significant risk to user security. Current mitigation strategies are not detailed in the articles, indicating an urgent need for awareness and defensive measures.

Key Points: • Attackers can hijack live sessions in Chrome and Edge via a new CDP technique. • The method requires prior code execution on Windows systems. • Sensitive browser data and authenticated sessions are at risk without cookie theft.

ThreatCluster AI How this analysis works

Timeline

2026-08-14
CDP attack technique disclosed
A new method for hijacking authenticated sessions in Chrome and Edge was revealed, exploiting the Chrome DevTools Protocol.
Thehackernews
2026-08-17
Details published on attack method
Further insights into the CDP attack were shared, highlighting its ability to bypass cookie theft protections.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story