Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Google Rolls Out Cookie Theft Protections in Chrome
    Cybersecurity

    Google Rolls Out Cookie Theft Protections in Chrome

    adminBy adminApril 12, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Chrome security
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google has announced the rollout of new session cookie protections in Chrome to prevent account compromise via stolen authentication cookies.

    The feature, called Device Bound Session Credentials (DBSC), was announced in April 2024 and has become available in Chrome 146 for Windows. macOS users will receive it as well, in a future browser release.

    DBSC fights session cookie theft by cryptographically binding authentication sessions to the user’s device, thus rendering stolen cookies useless.

    Typically stolen using information-stealing malware and often shared or sold on cybercrime platforms, these tokens may provide attackers with access to users’ accounts without a password.

    “Once sophisticated malware has gained access to a machine, it can read the local files and memory where browsers store authentication cookies. As a result, there is no reliable way to prevent cookie exfiltration using software alone on any operating system,” Google notes.

    DBSC relies on hardware-backed security modules to generate a unique public/private key pair, and Chrome issues new short-lived session cookies to prove it possesses the private key to the server.

    Advertisement. Scroll to continue reading.

    “Because attackers cannot steal this key, any exfiltrated cookies quickly expire and become useless to those attackers,” Google explains.

    Websites can adopt the protection through dedicated registration and refresh endpoints, and the browser handles the cryptography and cookie rotation, so that all web apps can continue to use standard cookies for access.

    According to Google, an early version of the protocol that was rolled out last year has demonstrated a significant reduction in session theft when DBSC was enabled.

    Because each browser session is backed by a different key, websites cannot use them to track users across sessions or sites. Furthermore, the device does not share identifiers or attestation data with the server to prevent fingerprinting and cross-site tracking.

    According to Google, DBSC was built as an open web standard through the W3C process, and Microsoft helped design it. Okta and other web platforms have tested DBSC, and implementation details have been included in a guide for web developers.

    Google is also working to secure federated identity by expanding DBSC to support cross-origin bindings, implementing advanced registration capabilities to tie DBSC sessions to pre-existing trusted key material, and potentially adding software-based keys to make protection available on devices that lack dedicated secure hardware.

    Related: Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome

    Related: Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

    Related: Sophisticated CrystalX RAT Emerges

    Related: Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

    Chrome cookie Google Protections rolls theft
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleDon’t buy a power bank until you see my 4 favorite picks for 20,000mAh and above
    Next Article ConnectBot v1.10.1 by Kenny Root
    admin
    • Website

    Related Posts

    Medium-severity flaw in Microsoft SharePoint exploited

    April 16, 2026

    Critical Nginx UI auth bypass flaw now actively exploited in the wild

    April 16, 2026

    Exploited Vulnerability Exposes Nginx Servers to Hacking

    April 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    MKBHD pulls back the curtain on LG’s cancelled rollable

    April 16, 2026

    Medium-severity flaw in Microsoft SharePoint exploited

    April 16, 2026

    Google’s New Gemini App for Mac Comes With Two Key Benefits (and One Drawback)

    April 16, 2026

    OpenAI pulls out of a second Stargate data center deal

    April 16, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,336)
    • Privacy & Online Earning (168)
    • SEO & Digital Marketing (819)
    • Tech Tools & Mobile / Apps (1,599)
    • WiFi / Internet & Networking (225)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    MKBHD pulls back the curtain on LG’s cancelled rollable

    April 16, 2026

    Medium-severity flaw in Microsoft SharePoint exploited

    April 16, 2026

    Google’s New Gemini App for Mac Comes With Two Key Benefits (and One Drawback)

    April 16, 2026
    Most Popular
    • MKBHD pulls back the curtain on LG’s cancelled rollable
    • Medium-severity flaw in Microsoft SharePoint exploited
    • Google’s New Gemini App for Mac Comes With Two Key Benefits (and One Drawback)
    • OpenAI pulls out of a second Stargate data center deal
    • Critical Nginx UI auth bypass flaw now actively exploited in the wild
    • How To Become An AI Search Authority In SEO [Webinar]
    • Android 17 stops apps from demanding access to all your contacts
    • Exploited Vulnerability Exposes Nginx Servers to Hacking
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.