VoidStealer Malware Bypasses Chrome ABE to Steal Sensitive Data

VoidStealer Malware Bypasses Chrome ABE to Steal Sensitive Data

First seen 22 Mar 2026, 14:57 UTC CybersecuritynewsBleepingcomputerGbhackersCsoonlineGround.News 83% similarity 64.5

Article Content

Browse articles
ThreatCluster

VoidStealer, a new infostealer malware, has been identified as the first to bypass Google Chrome's Application-Bound Encryption (ABE) using a novel debugger-based technique. This method allows it to extract the v20_master_key, which is crucial for decrypting sensitive browser data like passwords and cookies, directly from memory without requiring privilege escalation or code injection. The malware, which operates as a malware-as-a-service (MaaS) platform, was first observed in the wild in December 2025 and has rapidly evolved, with version 2.0 introducing this stealthy bypass method. Researchers from Gen Digital noted that while ABE was designed to protect sensitive data, the key still exists in plaintext during decryption operations, which VoidStealer exploits. The malware's technique involves attaching a debugger to a hidden browser process and setting hardware breakpoints to intercept the master key during its brief presence in memory. This development poses a significant risk to users of Chrome and other browsers utilizing ABE, as it represents a shift in the tactics employed by infostealers.

Key Points: • VoidStealer is the first malware to bypass Chrome's ABE using a debugger-based technique. • The malware extracts the v20_master_key from memory without needing privilege escalation or code injection. • VoidStealer operates as a malware-as-a-service and has rapidly evolved since its introduction.

ThreatCluster AI How this analysis works

Timeline

2025-12-15
VoidStealer first appeared on dark web forums.
2026-03-13
VoidStealer version 2.0 introduced new ABE bypass technique.
2026-03-20
Cybersecuritynews reports on the new VoidStealer variant.
2026-03-22
Bleepingcomputer publishes detailed analysis of VoidStealer.
2026-03-23
Csoonline and Gbhackers report on VoidStealer's impact.

Community

Browse all →

Tracked Entities in This Story