CYBER DELTA FORCESearch

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement , Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release.

CDF News DeskGoogle Security Blog9 Apr 2026, 10:41 pm
CDF REPORT

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement , Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

Crucially, once sophisticated malware has gained access to a machine, it can read the local files and memory where browsers store authentication cookies.

What changed

Historically, mitigating session theft relied on detecting the stolen credentials after the fact using a complex set of abuse heuristics – a reactive approach that persistent attackers could often circumvent.

Why this matters

Crucially, once sophisticated malware has gained access to a machine, it can read the local files and memory where browsers store authentication cookies.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Suspected Black Axe gang leaders face cybercrime charges in the USBleepingComputer · 15 Sept 2026, 3:20 pmMicrosoft confirms KB5002914 Excel update breaks copy and pasteBleepingComputer · 15 Sept 2026, 2:10 pmMicrosoft releases emergency Windows updates to fix RDS failuresBleepingComputer · 15 Sept 2026, 2:22 amMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaThe Record · 15 Sept 2026, 1:10 am