LIVE · cybersecurity feed
Live wire
chromehigh

Protecting Cookies with Device Bound Session Credentials

Google's Chrome browser is rolling out Device Bound Session Credentials (DBSC) to Windows users, with macOS support coming soon. This new feature aims to prevent session theft by cryptographically linking user sessions to a specific device. Previously, stolen session cookies could grant attackers access to accounts without needing passwords, but DBSC makes these exfiltrated cookies unusable, shifting defenses from reactive detection to proactive prevention.

zeroday.news · 114d ago

Google's Chrome browser is introducing a new security feature called Device Bound Session Credentials (DBSC) for Windows users, with support for macOS planned for the near future. This development is designed to significantly enhance protection against session hijacking, a common attack vector where attackers gain unauthorized access to user accounts by stealing session cookies.

Traditionally, if an attacker managed to obtain a user's session cookie, they could bypass the need for a password and impersonate the user, accessing their accounts. This often involved sophisticated phishing attacks or malware that could extract these cookies from a user's browser.

DBSC aims to neutralize this threat by creating a cryptographic link between a user's active session and the specific device they are using. This means that even if a session cookie is successfully stolen and transferred to another machine, it will be rendered useless.

The core principle behind DBSC is to ensure that session credentials are bound to the hardware of the device. This binding is achieved through cryptographic means, making it extremely difficult, if not impossible, for an attacker to use a stolen cookie on a different system.

This shift represents a move from a reactive security posture, which relies on detecting and responding to breaches after they occur, to a more proactive approach. By making stolen session cookies inherently unusable outside of their original device, DBSC aims to prevent session theft before it can be exploited.

The implementation of DBSC is expected to bolster the security of online accounts by adding a robust layer of protection against a prevalent attack method. Users will not need to take any specific action to enable this feature, as it will be integrated into the Chrome browser.

The rollout to Windows users is already underway, and the upcoming support for macOS indicates a broader strategy to secure user sessions across different platforms. This feature is a significant step forward in browser security, addressing a long-standing vulnerability in how online sessions are managed and protected.

By cryptographically tying sessions to the device, Chrome is making it substantially harder for attackers to leverage stolen cookies for malicious purposes. This proactive measure is designed to safeguard user data and privacy by rendering exfiltrated session information inert when attempted on unauthorized hardware.

chromesession theftmalwareauthenticationcookies
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]