Google Chrome's Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. The feature will be enabled by default for all Google Workspace customers, and administrators cannot disable it.
DBSC cryptographically binds session cookies to a specific device to prevent hackers from using stolen cookies to bypass multi-factor authentication (MFA) and hijack users' accounts. The technology works by linking user sessions to the hardware of the device, such as the Trusted Platform Module (TPM) on Windows or the Secure Enclave on macOS. Unique public and private keys generated by the device’s security chip encrypt and decrypt sensitive data, and because these keys cannot be extracted, stolen session cookies become unusable to attackers.
“DBSC strengthens account security after users are logged in and helps bind a session cookie — small files used by websites to remember user information — to the device a user authenticated from. Even if malware was present on the user's device, DBSC reduces the risk of session theft and makes it meaningfully more difficult for malicious actors to exploit stolen session cookies.” Google said. “DBSC fundamentally changes the web's capability to defend against this threat by shifting the paradigm from reactive detection to proactive prevention, ensuring that successfully exfiltrated cookies cannot be used to access users' accounts.”
The feature is now available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts. DBSC was first announced in 2024 and had been available in beta since April.
Google noted that threat actors have previously exploited stolen Google authentication cookies to access accounts. In some cases, malware operations like Lumma and Rhadamanthys claimed they could restore expired cookies to maintain access. Attackers have also abused the undocumented Google OAuth “MultiLogin” API endpoint to generate new authentication cookies after stolen ones expired.
The company previously advised users to remove malware from their devices and recommended enabling Chrome's Enhanced Safe Browsing mode to protect against phishing and malware. With DBSC now generally available, Google states that malicious actors should be effectively blocked from abusing stolen cookies because they will lack access to the cryptographic keys required to use them.
forum Comments (0)
No comments yet. Be the first to comment.