Google Chrome 146 Adds Device Bound Session Credentials to Stop Session Cookie Theft
#1
Information 
Quote:Google has introduced Device Bound Session Credentials in Chrome 146 for Windows. This security feature cryptographically ties session cookies to a device's hardware, making it impossible for stolen cookies to be used on a different machine.

Support for macOS has not been announced. The feature was first announced in 2024 and was developed in partnership with Microsoft as an open web standard.

How DBSC Works in Chrome 146 on Windows

[Image: Screenshot-2026-04-09-at-10.11.22-AM-scaled.png]

DBSC links a user's browser session to the device's security hardware, which is the Trusted Platform Module on Windows and the Secure Enclave on macOS. During session creation, the security chip generates a unique pair of public and private keys.

Since the private key can’t be exported from the device, any session cookie stolen by malware becomes useless elsewhere. Short-lived session cookies are only issued when Chrome can prove to the server that it possesses the corresponding private key. Without this proof, exfiltrated cookies will expire and cannot be used to authenticate the attacker to the target service.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.6.8 / 19.6.9 Update
Changes in 19.6.9 ...harlan4096 — 10:29
Privazer 4.0.121 (02 May 2026)
v4.0.121 (02 May 2...harlan4096 — 10:27
Sandboxie 1.17.5 / 5.72.5
Sandboxie-Plus v1....harlan4096 — 10:26
QOwnNotes
26.5.1 Added a Re...Kool — 15:17
XYplorer
What's new in Rele...Kool — 10:35

[-]
Birthdays
Today's Birthdays
avatar (28)Honor6
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (45)xclubDum
avatar (41)Stewartanilm
avatar (44)nikitaxople
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>