Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
EtherRAT Spreads via Scheduled Tasks in Compromised Windows Domains
August 5, 2026
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Home/CyberSecurity News/Google Chrome Device-Bound Sessions Go GA to Prevent Account Takeovers
CyberSecurity News

Google Chrome Device-Bound Sessions Go GA to Prevent Account Takeovers

Key Takeaways Google has launched Device Bound Session Credentials (DBSC) for Chrome on Windows, a new security feature designed to combat session cookie theft. DBSC cryptographically links session...

Emy Elsamnoudy
Emy Elsamnoudy
May 30, 2026 3 Min Read
57 0

Key Takeaways

  • Google has launched Device Bound Session Credentials (DBSC) for Chrome on Windows, a new security feature designed to combat session cookie theft.
  • DBSC cryptographically links session cookies to the user’s specific device, rendering stolen cookies useless on other machines and effectively thwarting “pass-the-cookie” attacks.
  • The feature is now generally available by default for all Google Workspace customers, Workspace Individual subscribers, and personal Google accounts, requiring no administrative action to enable.

Google has officially rolled out Device Bound Session Credentials (DBSC) for its Chrome browser on Windows, introducing a significant defense mechanism against the pervasive threat of session cookie hijacking. This new capability aims to neutralize one of the most common methods attackers use to bypass multi-factor authentication (MFA) and gain unauthorized access to user accounts.

Table Of Content

  • Key Takeaways
  • Rollout Timeline and Availability
  • What You Should Do

While previously available in a beta phase for Google Workspace users, DBSC is now universally enabled by default. This includes all Google Workspace customers, individuals subscribed to Workspace, and users leveraging personal Google accounts, providing a broad layer of protection across Google’s ecosystem.

Session cookies are fundamental to how websites maintain user authentication, allowing users to remain logged in without re-entering credentials for every interaction. However, these small data files have become prime targets for cybercriminals. Malware, particularly info-stealer trojans, routinely extracts these cookies from compromised systems. Attackers then use these stolen cookies to hijack active user sessions, a technique known as a “pass-the-cookie” attack, which circumvents even robust MFA protections.

DBSC directly addresses this vulnerability by employing cryptography to bind a session cookie to the specific device from which a user initially authenticated. The practical implication is that if a threat actor manages to steal a cookie from a compromised endpoint, that cookie becomes invalid and unusable on any other machine. This innovation substantially increases the difficulty and cost for attackers who rely on stolen session tokens for persistent access and account takeovers.

Enhancing its protective capabilities, Google has integrated DBSC with its Context-Aware Access (CAA) framework. Organizations utilizing both features can implement more precise access policies. These policies can factor in various signals, including device attributes, user behavior patterns, and environmental conditions, adding an extra layer of verification beyond the initial login process.

For administrators, Google Workspace now offers the ability to monitor DBSC binding events through the security investigation tool’s audit logs. This provides security teams with critical visibility, allowing them to detect anomalies and track the integrity of user sessions across their entire environment.

A key aspect of DBSC is its seamless deployment: it activates automatically and does not require any administrative configuration. Furthermore, it cannot be disabled via the Admin console, ensuring its widespread and consistent application.

Rollout Timeline and Availability

Google commenced a phased rollout of DBSC on May 25, 2026, targeting both Rapid Release and Scheduled Release domains. Full feature availability is projected within 60 days of this date. The feature is broadly accessible to:

  • All Google Workspace customers
  • Workspace Individual subscribers
  • Users with personal Google accounts

DBSC signifies a pivotal shift in post-authentication security architecture. Instead of solely relying on perimeter defenses or MFA at the point of login, it extends trust verification throughout the entire duration of a user’s session. This architectural change significantly mitigates the risk of credential-based lateral movement and post-exploitation persistence tactics frequently employed by sophisticated threat actors.

What You Should Do

  • For enterprise security teams, regularly review audit logs within the Google Admin console to establish a baseline of normal DBSC binding behavior.
  • Actively monitor for any deviations from established DBSC binding patterns, as these could indicate active session hijacking attempts or compromised endpoints.
  • Ensure your organization’s security awareness training emphasizes the importance of device hygiene and avoiding suspicious links or downloads that could lead to info-stealer infections.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Palo Alto Networks PAN-OS Auth Bypass CVE-2024-3400 Exploited

Next Post

GreyVibe Hackers Use ChatGPT, Google Gemini to Power Cyberattacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI Agents Mythos 5, GPT-5.6-Sol Escaped Cybersecurity Sandbox to Attack Real Systems
August 5, 2026
CISA Warns of Apache Tomcat Encryption Flaw Actively Exploited
August 5, 2026
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us