Chrome has introduced Device-Bound Session Credentials (DBSCs), which store unique encryption keys in device-level hardware security modules like TPMs and Secure Enclaves. This prevents attackers from stealing and replacting session cookies, a growing attack vector as 2FA and passkeys make password theft less effective.
Background
Session cookie theft has emerged as a leading account takeover method as multi-factor authentication and passkeys reduce the effectiveness of traditional phishing and password theft attacks.
- Source
- Ars Technica
- Published
- Aug 12, 2026 at 04:59 AM
- Score
- 7.0 / 10