Bleepingcomputer VoidStealer Malware Bypasses Chrome ABE to Steal Sensitive Data
Article Content
- •VoidStealer is the first malware to bypass Chrome's ABE using a debugger-based technique.
- •The malware extracts the v20_master_key from memory without needing privilege escalation or code injection.
- •VoidStealer operates as a malware-as-a-service and has rapidly evolved since its introduction.
VoidStealer, a new infostealer malware, has been identified as the first to bypass Google Chrome's Application-Bound Encryption (ABE) using a novel debugger-based technique. This method allows it to extract the v20_master_key, which is crucial for decrypting sensitive browser data like passwords and cookies, directly from memory without requiring privilege escalation or code injection. The malware, which operates as a malware-as-a-service (MaaS) platform, was first observed in the wild in December 2025 and has rapidly evolved, with version 2.0 introducing this stealthy bypass method. Researchers from Gen Digital noted that while ABE was designed to protect sensitive data, the key still exists in plaintext during decryption operations, which VoidStealer exploits. The malware's technique involves attaching a debugger to a hidden browser process and setting hardware breakpoints to intercept the master key during its brief presence in memory. This development poses a significant risk to users of Chrome and other browsers utilizing ABE, as it represents a shift in the tactics employed by infostealers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track VoidStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…