Google Chrome Device-Bound Sessions Go GA to Prevent Account Takeovers
Key Takeaways Google has launched Device Bound Session Credentials (DBSC) for Chrome on Windows, a new security feature designed to combat session cookie theft. DBSC cryptographically links session...
Key Takeaways
- Google has launched Device Bound Session Credentials (DBSC) for Chrome on Windows, a new security feature designed to combat session cookie theft.
- DBSC cryptographically links session cookies to the user’s specific device, rendering stolen cookies useless on other machines and effectively thwarting “pass-the-cookie” attacks.
- The feature is now generally available by default for all Google Workspace customers, Workspace Individual subscribers, and personal Google accounts, requiring no administrative action to enable.
Google has officially rolled out Device Bound Session Credentials (DBSC) for its Chrome browser on Windows, introducing a significant defense mechanism against the pervasive threat of session cookie hijacking. This new capability aims to neutralize one of the most common methods attackers use to bypass multi-factor authentication (MFA) and gain unauthorized access to user accounts.
Table Of Content
While previously available in a beta phase for Google Workspace users, DBSC is now universally enabled by default. This includes all Google Workspace customers, individuals subscribed to Workspace, and users leveraging personal Google accounts, providing a broad layer of protection across Google’s ecosystem.
Session cookies are fundamental to how websites maintain user authentication, allowing users to remain logged in without re-entering credentials for every interaction. However, these small data files have become prime targets for cybercriminals. Malware, particularly info-stealer trojans, routinely extracts these cookies from compromised systems. Attackers then use these stolen cookies to hijack active user sessions, a technique known as a “pass-the-cookie” attack, which circumvents even robust MFA protections.
DBSC directly addresses this vulnerability by employing cryptography to bind a session cookie to the specific device from which a user initially authenticated. The practical implication is that if a threat actor manages to steal a cookie from a compromised endpoint, that cookie becomes invalid and unusable on any other machine. This innovation substantially increases the difficulty and cost for attackers who rely on stolen session tokens for persistent access and account takeovers.
Enhancing its protective capabilities, Google has integrated DBSC with its Context-Aware Access (CAA) framework. Organizations utilizing both features can implement more precise access policies. These policies can factor in various signals, including device attributes, user behavior patterns, and environmental conditions, adding an extra layer of verification beyond the initial login process.
For administrators, Google Workspace now offers the ability to monitor DBSC binding events through the security investigation tool’s audit logs. This provides security teams with critical visibility, allowing them to detect anomalies and track the integrity of user sessions across their entire environment.
A key aspect of DBSC is its seamless deployment: it activates automatically and does not require any administrative configuration. Furthermore, it cannot be disabled via the Admin console, ensuring its widespread and consistent application.
Rollout Timeline and Availability
Google commenced a phased rollout of DBSC on May 25, 2026, targeting both Rapid Release and Scheduled Release domains. Full feature availability is projected within 60 days of this date. The feature is broadly accessible to:
- All Google Workspace customers
- Workspace Individual subscribers
- Users with personal Google accounts
DBSC signifies a pivotal shift in post-authentication security architecture. Instead of solely relying on perimeter defenses or MFA at the point of login, it extends trust verification throughout the entire duration of a user’s session. This architectural change significantly mitigates the risk of credential-based lateral movement and post-exploitation persistence tactics frequently employed by sophisticated threat actors.
What You Should Do
- For enterprise security teams, regularly review audit logs within the Google Admin console to establish a baseline of normal DBSC binding behavior.
- Actively monitor for any deviations from established DBSC binding patterns, as these could indicate active session hijacking attempts or compromised endpoints.
- Ensure your organization’s security awareness training emphasizes the importance of device hygiene and avoiding suspicious links or downloads that could lead to info-stealer infections.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.