Google has made Device Bound Session Credentials (DBSC) generally available in Chrome for all users. DBSC cryptographically binds session cookies to a specific device's hardware security chip (TPM on Windows, Secure Enclave on macOS), making stolen cookies useless to attackers since they lack the required private keys. The feature rolls out automatically to all Google Workspace customers, Workspace Individual subscribers, and personal Google account users, and cannot be disabled by administrators. This directly counters infostealer malware like Lumma and Rhadamanthys that previously exploited stolen or revived session cookies to bypass MFA and hijack accounts.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
62.6K Impressions10 Comments