By using this site, you agree to our Privacy Policy and Terms of Use.
Accept
VellaTimesVellaTimesVellaTimes
  • News
    NewsShow More
    A split-screen visual contrasting a vibrant, healthy rainforest ecosystem with a wooden legal gavel, representing the intersection of nature and environmental law.
    Global Environmental Conservation Faces New Climate Challenges and Legal Shifts
    April 10, 2026
    A glowing digital padlock shattering into data fragments in a dimly lit corporate server room with flashing red warning lights.
    Mercor Data Breach: $10 Billion AI Startup Faces Lawsuits and Customer Exodus
    April 10, 2026
    A glowing DNA double helix with one highlighted genetic letter in a modern laboratory setting.
    Single DNA Letter Change Triggers Complete Sex Reversal in Mice
    April 10, 2026
    A modern financial trading floor with glowing digital screens displaying downward stock market trends and a subtle artificial intelligence neural network graphic in the background.
    2026 Global Market Trends: AI Fears and Profit Shifts
    April 10, 2026
    A close-up view of a high-tech processor chip inside a brightly lit, modern data center server rack.
    Intel and Google Expand AI Infrastructure Partnership
    April 10, 2026
  • Technology
    TechnologyShow More
    A close-up view of a high-tech processor chip inside a brightly lit, modern data center server rack.
    Intel and Google Expand AI Infrastructure Partnership
    April 10, 2026
    A glowing digital brain floating above a sleek corporate server room representing Meta's advanced artificial intelligence model.
    Meta Enters Superintelligence Race With New Muse Spark AI Model
    April 10, 2026
    A modern computer monitor displaying a dynamic dashboard that transforms text into charts and prototypes in a collaborative corporate office setting.
    Atlassian Launches AI Visual Tools and Partner Agents for Confluence
    April 9, 2026
    A glowing artificial intelligence microchip resting on an upward-trending financial chart in a modern corporate setting.
    Samsung Reports Record $38B Q1 Profit Amid AI Chip Boom
    April 9, 2026
    A modern smartphone displaying a voice dictation interface on a sleek wooden desk in a well-lit professional workspace.
    Google Launches Free AI Edge Eloquent Offline Dictation App for iOS
    April 9, 2026
  • AI
    AIShow More
    A glowing digital padlock shattering into data fragments in a dimly lit corporate server room with flashing red warning lights.
    Mercor Data Breach: $10 Billion AI Startup Faces Lawsuits and Customer Exodus
    April 10, 2026
    A modern financial trading floor with glowing digital screens displaying downward stock market trends and a subtle artificial intelligence neural network graphic in the background.
    2026 Global Market Trends: AI Fears and Profit Shifts
    April 10, 2026
    A futuristic computer screen displaying glowing code in a modern, brightly lit server room, representing the newly launched ChatGPT Pro plan for Codex users.
    ChatGPT Pro Plan: $100 OpenAI Tier Launched for Codex
    April 10, 2026
    A group of journalists protesting outside a city office building holding signs demanding fair contracts and AI protections.
    ProPublica Union Launches 24-Hour Strike Over AI Protections and Pay
    April 9, 2026
    A glowing Samsung semiconductor microchip on a sleek glass surface inside a modern artificial intelligence data center.
    Samsung Q1 Profit Surges Eightfold as AI Chip Demand Drives Record Earnings
    April 9, 2026
  • Science
    ScienceShow More
    A split-screen visual contrasting a vibrant, healthy rainforest ecosystem with a wooden legal gavel, representing the intersection of nature and environmental law.
    Global Environmental Conservation Faces New Climate Challenges and Legal Shifts
    April 10, 2026
    A glowing DNA double helix with one highlighted genetic letter in a modern laboratory setting.
    Single DNA Letter Change Triggers Complete Sex Reversal in Mice
    April 10, 2026
    The Orion spacecraft capsule splashing down in the Pacific Ocean under three large orange and white parachutes during the Artemis II mission return.
    Artemis II Return to Earth: Crew Prepares for Historic Pacific Splashdown
    April 10, 2026
    A medical researcher in a modern laboratory analyzing glowing digital DNA sequences and molecular structures on an advanced screen.
    KRAS Targeted Therapy: New Advances in Cancer Care
    April 9, 2026
    News-style illustration of a particle physics setting with glowing particle tracks emerging from a dark quantum vacuum concept scene.
    Quantum Vacuum Study Shows How Visible Matter Forms
    April 9, 2026
  • World
    WorldShow More
    Allu Arjun Commitment to Ethical Brand Partnerships
    Exploring Allu Arjun’s Commitment to Ethical Brand Partnerships
    December 18, 2023
    Orry aka Orhan Awatramani
    Orhan Awatramani ‘Orry’ Biography, Lifestyle and Rise to Fame
    December 8, 2023
    Alia Bhatt Latest Deepake Video Victim
    Alia Bhatt becomes latest victim of Deepfake Videos, Obscene Video goes Viral
    November 28, 2023
    Napoleon Movie Review
    Napoleon Movie Review: A Historical Epic by Ridley Scott Reviewed
    November 25, 2023
  • Bookmarks
Search
Category
  • News
  • Technology
  • AI
  • Science
  • World
Company
  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy
Resources
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
Reading: Google Chrome Launches Device Bound Session Credentials to Stop Cookie Theft
Share
Notification Show More
Font ResizerAa
VellaTimesVellaTimes
Font ResizerAa
  • News
  • Technology
  • AI
  • Science
  • World
Search
  • Explore
    • News
    • Technology
    • AI
    • Science
    • World
  • Useful Links
    • About Us
    • Contact Us
    • Fact Checking Policy
    • Terms & Conditions
    • Privacy Policy
    • Copyright Policy
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
News

Google Chrome Launches Device Bound Session Credentials to Stop Cookie Theft

Rakesh Paul
Last updated: 10/04/2026
Rakesh Paul
Share
7 Min Read
A glowing digital padlock and web browser window secured above a computer microchip, representing Google Chrome's hardware-bound cookie protection.

Google has officially rolled out a new security feature for Windows users on Chrome 146 designed to block info-stealing malware from harvesting session cookies. Known as Device Bound Session Credentials (DBSC), this proactive security measure aims to disrupt the thriving market for stolen browser cookies by making exfiltrated data completely useless to attackers.

Contents
How Device Bound Session Credentials Prevent Session HijackingWhy Cookie Theft Has Become a Major Security ThreatPrivacy and Open Web StandardsFuture Improvements for Enterprise Security

Initially announced in April 2024, the public availability of Device Bound Session Credentials fundamentally changes how web browsers defend against session hijacking. While Windows users are the first to receive this update, Google has confirmed that macOS users will benefit from the exact same security feature in an upcoming Chrome release.

How Device Bound Session Credentials Prevent Session Hijacking

Traditionally, mitigating session theft relied on reactive detection methods and complex abuse heuristics to identify stolen credentials after an attack occurred. Persistent threat actors could often circumvent these measures. Device Bound Session Credentials shift the paradigm from reactive detection to proactive prevention by cryptographically binding authentication sessions to a user’s specific device.

When a user authenticates, Chrome generates a unique public and private key pair. The issuance of new, short-lived session cookies relies entirely on the browser proving possession of the corresponding private key to the server. Because the private key cannot be exported from the machine, attackers who manage to exfiltrate the session cookie cannot authenticate without access to the user’s actual device. Without the private key, the stolen cookies expire almost immediately and become entirely useless.

The Role of Hardware Security Modules

To ensure the private keys remain secure, Device Bound Session Credentials rely on hardware-backed security modules built directly into modern computers. On Windows systems, this process utilizes the Trusted Platform Module (TPM). For Apple devices, the cryptographic keys will be secured using the macOS Secure Enclave.

By tying the session securely to the device’s physical hardware, Google ensures that the unique private key protecting the sensitive session data cannot be extracted, even if sophisticated malware gains access to local files and memory where authentication cookies are stored.

Why Cookie Theft Has Become a Major Security Threat

Session cookies act as authentication tokens created on the server side based on a user’s login credentials. Because they allow users to remain authenticated to a service without repeatedly providing a password, they typically have extended lifetimes.

Threat actors deploy specialized info-stealing malware, such as the LummaC2 family, to silently extract existing session cookies from a browser or wait for a user to log into new accounts. Hackers can then use these stolen cookies to gain unauthorized access to user accounts. This stolen access is frequently bundled, traded, or sold among malicious actors.

Because sophisticated malware can easily read the local files where browsers store cookies, Google noted that there is no reliable way to prevent cookie exfiltration using software alone on any operating system.

Real-World Consequences of Stolen Cookies

The threat of session hijacking is not merely theoretical. In 2023, the popular YouTube channel Linus Tech Tips suffered a high-profile breach due to this exact type of attack. An employee inadvertently opened a malicious PDF file that allowed malware to steal the employee’s browser cookies. Attackers then used those exfiltrated cookies to bypass login screens, access the company’s social media accounts, and post cryptocurrency scams. With Device Bound Session Credentials fully implemented, this specific attack vector would be completely blocked, as the stolen cookies would not function outside of the employee’s physical computer.

Privacy and Open Web Standards

While increasing security, Google built the Device Bound Session Credentials protocol to be private by design. Each individual web session is backed by a distinct cryptographic key. This separation prevents websites from correlating a user’s activity across multiple sessions or sites on the same device.

Furthermore, the protocol minimizes information exchange. It only requires the per-session public key necessary to prove possession, ensuring that it does not leak device identifiers or attestation data to the server. This prevents the security feature from being misused for cross-site tracking or device fingerprinting.

To ensure broad compatibility, Google partnered with Microsoft and engaged with the Web Application Security Working Group to develop the protocol as an open web standard through the W3C process. Over the past year, Google also conducted two Origin Trials, receiving essential feedback from web platforms like Okta. Web developers can now upgrade to hardware-bound sessions by adding dedicated registration and refresh endpoints to their backends without altering their existing front-end architecture.

Future Improvements for Enterprise Security

As the Device Bound Session Credentials standard evolves, Google plans to introduce advanced capabilities tailored for complex enterprise environments. Key areas of ongoing development include:

  • Securing Federated Identity: Google is expanding the protocol to support cross-origin bindings for Single Sign-On (SSO) environments. This ensures that a relying party session remains bound to the original device key used by the Identity Provider, maintaining an unbroken chain of trust throughout the federated login process.
  • Advanced Registration Capabilities: For environments requiring stricter security, Google is developing mechanisms to bind sessions to pre-existing trusted key material, such as mTLS certificates or hardware security keys, rather than generating new keys at sign-in.
  • Broader Device Support: To protect devices that lack dedicated secure hardware, Google is actively exploring the addition of software-based keys.
TAGGED: Cookie Theft, cybersecurity, DBSC, Google Chrome, Infostealer Malware, Session Hijacking, TPM, Web Security
Share This Article
Facebook Twitter Whatsapp Whatsapp Telegram Copy Link
By Rakesh Paul
I'm the Co-Founder of VellaTimes and an experienced digital marketer. With substantial experience in the blogging industry, I love crafting insightful and engaging news articles on technology, sports, and automobiles.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Read

Spot AI Introduces Universal AI Agent Builder for Cameras

February 22, 2026

Real-Time Qubit Tracking: A Quantum Computing Breakthrough

February 22, 2026

Big Tech AI Spending Drives 2026 Infrastructure Boom

February 20, 2026

Google Gemini Memory Import Tool Makes Switching Easy

March 30, 2026

GPT-5.3 Codex launches as faster agentic coding model

February 14, 2026

New Breath Sensor Rapidly Detects Pneumonia Biomarkers

April 4, 2026

Related News

A split-screen visual contrasting a vibrant, healthy rainforest ecosystem with a wooden legal gavel, representing the intersection of nature and environmental law.
News

Global Environmental Conservation Faces New Climate Challenges and Legal Shifts

Nisha Pradhan Nisha Pradhan April 10, 2026
A glowing digital padlock shattering into data fragments in a dimly lit corporate server room with flashing red warning lights.
News

Mercor Data Breach: $10 Billion AI Startup Faces Lawsuits and Customer Exodus

Sameer Katoch Sameer Katoch April 10, 2026
A glowing DNA double helix with one highlighted genetic letter in a modern laboratory setting.
News

Single DNA Letter Change Triggers Complete Sex Reversal in Mice

Nisha Pradhan Nisha Pradhan April 10, 2026

About Us

VellaTimesVellaTimesVellaTimes

VellaTimes is a leading news portal that covers the latest trending news in technology, lifestyle, entertainment, automobiles, travel, and sports.

Explore

  • News
  • Technology
  • AI
  • Science
  • World

Useful Links

  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy

Subscribe Us

Subscribe to our newsletter for the Latest News and Top Stories!

© 2022 VellaTimes • All Rights Reserved.
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
adbanner
AdBlocker Detected
Our site is an advertising supported site. Please whitelist us to support our work.
Okay, I'll Whitelist