By using this site, you agree to our Privacy Policy and Terms of Use.
Accept
VellaTimesVellaTimesVellaTimes
  • News
    NewsShow More
    Close-up of a silver espresso machine extracting a fresh shot of coffee into a glass cup in a softly lit cafe setting.
    Espresso Extraction Science: The Finer Grind Flaw
    May 18, 2026
    A smartphone resting on a wooden desk displaying an AI-powered Amazon search bar in a modern home office setting.
    Amazon Alexa for Shopping Replaces Rufus AI Assistant
    May 18, 2026
    Wide news-style image showing an OpenAI office scene with screens displaying audio waveforms and voice technology graphics
    OpenAI acquires Weights.gg to boost voice AI tools
    May 18, 2026
    Federal agents standing outside a modern university biology laboratory building at dusk during an active investigation.
    US Arrests Chinese Scientists for Smuggling Biological Materials
    May 18, 2026
    A dramatically lit modern corporate courtroom with futuristic technology elements, representing a high-stakes artificial intelligence legal trial.
    Elon Musk OpenAI Lawsuit Exposes Clashes Over AI Safety
    May 18, 2026
  • Technology
    TechnologyShow More
    Wide news-style image showing an OpenAI office scene with screens displaying audio waveforms and voice technology graphics
    OpenAI acquires Weights.gg to boost voice AI tools
    May 18, 2026
    A polished silicon wafer rests on a surface inside a modern semiconductor manufacturing facility.
    Samsung Strike Threatens Global AI Chip Production
    May 18, 2026
    A glowing computer screen displaying the text GPT-5.5 Instant in a modern, high-tech office environment with soft blue and purple lighting.
    GPT-5.5 Instant: OpenAI’s New Default ChatGPT Model
    May 10, 2026
    Wide view of a modern AI data center with server racks, glowing fiber-optic cables, and semiconductor hardware in the foreground.
    AI Infrastructure Spending Drives Nvidia, AMD Shares
    May 10, 2026
    A glowing computer monitor displaying lines of code and digital network graphics in a modern tech office setting.
    Airbnb AI Coding: 60% of New Software Now Generated by AI
    May 9, 2026
  • AI
    AIShow More
    A smartphone resting on a wooden desk displaying an AI-powered Amazon search bar in a modern home office setting.
    Amazon Alexa for Shopping Replaces Rufus AI Assistant
    May 18, 2026
    A dramatically lit modern corporate courtroom with futuristic technology elements, representing a high-stakes artificial intelligence legal trial.
    Elon Musk OpenAI Lawsuit Exposes Clashes Over AI Safety
    May 18, 2026
    A high-tech global map visualization showing glowing digital connections across different continents, representing the worldwide adoption of artificial intelligence.
    Global AI Adoption in 2026: Trends and Growing Divide
    May 10, 2026
    A modern smartphone displaying an artificial intelligence chat interface used for online shopping and product comparison.
    Alibaba Qwen AI Taobao Integration Launches Agentic Shopping
    May 10, 2026
    A split-screen illustration showing a high-tech modern office using advanced AI tools contrasted against an older, dimly lit workspace.
    Global AI Adoption Surges But Rich-Poor Divide Widens
    May 9, 2026
  • Science
    ScienceShow More
    Close-up of a silver espresso machine extracting a fresh shot of coffee into a glass cup in a softly lit cafe setting.
    Espresso Extraction Science: The Finer Grind Flaw
    May 18, 2026
    Federal agents standing outside a modern university biology laboratory building at dusk during an active investigation.
    US Arrests Chinese Scientists for Smuggling Biological Materials
    May 18, 2026
    Header image of a quantum communication lab setup with fiber-optic equipment, a telecom quantum dot device, and interferometer components used for long-distance quantum key distribution.
    Quantum Key Distribution Reaches 120 km With Quantum Dots
    May 10, 2026
    Abstract geometric representation of glowing quantum paraparticles interacting within a three-dimensional mathematical grid in deep blue and gold tones.
    Quantum Paraparticles Exist: New Math Challenges Physics
    May 10, 2026
    A large expedition cruise ship is navigating rough ocean waters under a cloudy sky.
    Global Authorities Respond to Andes Hantavirus Outbreak on MV Hondius Cruise Ship
    May 9, 2026
  • World
    WorldShow More
    Allu Arjun Commitment to Ethical Brand Partnerships
    Exploring Allu Arjun’s Commitment to Ethical Brand Partnerships
    December 18, 2023
    Orry aka Orhan Awatramani
    Orhan Awatramani ‘Orry’ Biography, Lifestyle and Rise to Fame
    December 8, 2023
    Alia Bhatt Latest Deepake Video Victim
    Alia Bhatt becomes latest victim of Deepfake Videos, Obscene Video goes Viral
    November 28, 2023
    Napoleon Movie Review
    Napoleon Movie Review: A Historical Epic by Ridley Scott Reviewed
    November 25, 2023
  • Bookmarks
Search
Category
  • News
  • Technology
  • AI
  • Science
  • World
Company
  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy
Resources
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
Reading: Google Chrome Launches Device Bound Session Credentials to Stop Cookie Theft
Share
Notification Show More
Font ResizerAa
VellaTimesVellaTimes
Font ResizerAa
  • News
  • Technology
  • AI
  • Science
  • World
Search
  • Explore
    • News
    • Technology
    • AI
    • Science
    • World
  • Useful Links
    • About Us
    • Contact Us
    • Fact Checking Policy
    • Terms & Conditions
    • Privacy Policy
    • Copyright Policy
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
News

Google Chrome Launches Device Bound Session Credentials to Stop Cookie Theft

Rakesh Paul
Last updated: 10/04/2026
Rakesh Paul
Share
7 Min Read
A glowing digital padlock and web browser window secured above a computer microchip, representing Google Chrome's hardware-bound cookie protection.

Google has officially rolled out a new security feature for Windows users on Chrome 146 designed to block info-stealing malware from harvesting session cookies. Known as Device Bound Session Credentials (DBSC), this proactive security measure aims to disrupt the thriving market for stolen browser cookies by making exfiltrated data completely useless to attackers.

Contents
How Device Bound Session Credentials Prevent Session HijackingWhy Cookie Theft Has Become a Major Security ThreatPrivacy and Open Web StandardsFuture Improvements for Enterprise Security

Initially announced in April 2024, the public availability of Device Bound Session Credentials fundamentally changes how web browsers defend against session hijacking. While Windows users are the first to receive this update, Google has confirmed that macOS users will benefit from the exact same security feature in an upcoming Chrome release.

How Device Bound Session Credentials Prevent Session Hijacking

Traditionally, mitigating session theft relied on reactive detection methods and complex abuse heuristics to identify stolen credentials after an attack occurred. Persistent threat actors could often circumvent these measures. Device Bound Session Credentials shift the paradigm from reactive detection to proactive prevention by cryptographically binding authentication sessions to a user’s specific device.

When a user authenticates, Chrome generates a unique public and private key pair. The issuance of new, short-lived session cookies relies entirely on the browser proving possession of the corresponding private key to the server. Because the private key cannot be exported from the machine, attackers who manage to exfiltrate the session cookie cannot authenticate without access to the user’s actual device. Without the private key, the stolen cookies expire almost immediately and become entirely useless.

The Role of Hardware Security Modules

To ensure the private keys remain secure, Device Bound Session Credentials rely on hardware-backed security modules built directly into modern computers. On Windows systems, this process utilizes the Trusted Platform Module (TPM). For Apple devices, the cryptographic keys will be secured using the macOS Secure Enclave.

By tying the session securely to the device’s physical hardware, Google ensures that the unique private key protecting the sensitive session data cannot be extracted, even if sophisticated malware gains access to local files and memory where authentication cookies are stored.

Why Cookie Theft Has Become a Major Security Threat

Session cookies act as authentication tokens created on the server side based on a user’s login credentials. Because they allow users to remain authenticated to a service without repeatedly providing a password, they typically have extended lifetimes.

Threat actors deploy specialized info-stealing malware, such as the LummaC2 family, to silently extract existing session cookies from a browser or wait for a user to log into new accounts. Hackers can then use these stolen cookies to gain unauthorized access to user accounts. This stolen access is frequently bundled, traded, or sold among malicious actors.

Because sophisticated malware can easily read the local files where browsers store cookies, Google noted that there is no reliable way to prevent cookie exfiltration using software alone on any operating system.

Real-World Consequences of Stolen Cookies

The threat of session hijacking is not merely theoretical. In 2023, the popular YouTube channel Linus Tech Tips suffered a high-profile breach due to this exact type of attack. An employee inadvertently opened a malicious PDF file that allowed malware to steal the employee’s browser cookies. Attackers then used those exfiltrated cookies to bypass login screens, access the company’s social media accounts, and post cryptocurrency scams. With Device Bound Session Credentials fully implemented, this specific attack vector would be completely blocked, as the stolen cookies would not function outside of the employee’s physical computer.

Privacy and Open Web Standards

While increasing security, Google built the Device Bound Session Credentials protocol to be private by design. Each individual web session is backed by a distinct cryptographic key. This separation prevents websites from correlating a user’s activity across multiple sessions or sites on the same device.

Furthermore, the protocol minimizes information exchange. It only requires the per-session public key necessary to prove possession, ensuring that it does not leak device identifiers or attestation data to the server. This prevents the security feature from being misused for cross-site tracking or device fingerprinting.

To ensure broad compatibility, Google partnered with Microsoft and engaged with the Web Application Security Working Group to develop the protocol as an open web standard through the W3C process. Over the past year, Google also conducted two Origin Trials, receiving essential feedback from web platforms like Okta. Web developers can now upgrade to hardware-bound sessions by adding dedicated registration and refresh endpoints to their backends without altering their existing front-end architecture.

Future Improvements for Enterprise Security

As the Device Bound Session Credentials standard evolves, Google plans to introduce advanced capabilities tailored for complex enterprise environments. Key areas of ongoing development include:

  • Securing Federated Identity: Google is expanding the protocol to support cross-origin bindings for Single Sign-On (SSO) environments. This ensures that a relying party session remains bound to the original device key used by the Identity Provider, maintaining an unbroken chain of trust throughout the federated login process.
  • Advanced Registration Capabilities: For environments requiring stricter security, Google is developing mechanisms to bind sessions to pre-existing trusted key material, such as mTLS certificates or hardware security keys, rather than generating new keys at sign-in.
  • Broader Device Support: To protect devices that lack dedicated secure hardware, Google is actively exploring the addition of software-based keys.
TAGGED: Cookie Theft, cybersecurity, DBSC, Google Chrome, Infostealer Malware, Session Hijacking, TPM, Web Security
Share This Article
Facebook Twitter Whatsapp Whatsapp Telegram Copy Link
By Rakesh Paul
I'm the Co-Founder of VellaTimes and an experienced digital marketer. With substantial experience in the blogging industry, I love crafting insightful and engaging news articles on technology, sports, and automobiles.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Read

Urgent CDC Warnings Amid Chikungunya Virus Outbreaks

March 30, 2026

OpenAI funding round talks: Nvidia, Amazon, Microsoft

January 29, 2026

Drone Strikes Damage Amazon Data Centers in UAE and Bahrain

March 3, 2026

CES 2026 AI: Robots, cars and physical AI take over

January 10, 2026

Webb Telescope Discovers Most Distant Galaxy Ever Observed

January 31, 2026

Microsoft Maia 200 AI chip boosts Azure inference

January 27, 2026

Related News

Close-up of a silver espresso machine extracting a fresh shot of coffee into a glass cup in a softly lit cafe setting.
News

Espresso Extraction Science: The Finer Grind Flaw

Nisha Pradhan Nisha Pradhan May 18, 2026
A smartphone resting on a wooden desk displaying an AI-powered Amazon search bar in a modern home office setting.
News

Amazon Alexa for Shopping Replaces Rufus AI Assistant

Sameer Katoch Sameer Katoch May 18, 2026
Wide news-style image showing an OpenAI office scene with screens displaying audio waveforms and voice technology graphics
News

OpenAI acquires Weights.gg to boost voice AI tools

Rakesh Paul Rakesh Paul May 18, 2026

About Us

VellaTimesVellaTimesVellaTimes

VellaTimes is a leading news portal that covers the latest trending news in technology, lifestyle, entertainment, automobiles, travel, and sports.

Explore

  • News
  • Technology
  • AI
  • Science
  • World

Useful Links

  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy

Subscribe Us

Subscribe to our newsletter for the Latest News and Top Stories!

© 2022 VellaTimes • All Rights Reserved.
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
adbanner
AdBlocker Detected
Our site is an advertising supported site. Please whitelist us to support our work.
Okay, I'll Whitelist