VoidStealer Malware Bypasses Chrome Encryption to Steal Passwords and Cookies
Key Takeaways A new malware, VoidStealer, is actively bypassing Google Chrome’s App-Bound Encryption on Windows. The malware targets stored passwords and session cookies, impacting Chrome and...
Key Takeaways
- A new malware, VoidStealer, is actively bypassing Google Chrome’s App-Bound Encryption on Windows.
- The malware targets stored passwords and session cookies, impacting Chrome and other Chromium-based browsers like Edge and Brave.
- VoidStealer operates as Malware-as-a-Service (MaaS), making it broadly accessible to cybercriminals.
- The threat is severe, as it allows attackers to hijack accounts without needing passwords.
A recently uncovered malware variant, dubbed VoidStealer, presents a significant threat to Windows users of Google Chrome and other Chromium-based browsers. This sophisticated infostealer employs a novel method to circumvent a critical security feature designed to protect sensitive user data.
Table Of Content
VoidStealer specifically targets Chrome’s App-Bound Encryption, a protective layer Google implemented to safeguard stored passwords and session cookies from unauthorized access. What distinguishes VoidStealer is its ability to bypass this defense without requiring elevated system privileges, a notable achievement in modern malware development.
Google introduced App-Bound Encryption in July 2024 with Chrome version 127. Its purpose was to tightly link the browser’s encryption key to the Chrome application itself. The security architecture relied on a privileged service to prevent any external program from requesting this key, thereby rendering stored data inaccessible to stealers. For a period, this mechanism proved reasonably effective.
Analysts at Kaspersky identified and extensively analyzed VoidStealer, observing its emergence in March 2026. The malware functions under a Malware-as-a-Service (MaaS) model, meaning its developers lease the ready-to-use tool to other threat actors, significantly broadening its reach among cybercriminals.
In a report shared with Cyber Security News (CSN), Kaspersky highlighted VoidStealer’s bypass technique as both innovative and highly effective against current browser security measures.
Rather than attempting to directly steal the encryption key, VoidStealer patiently waits for Chrome to decrypt its own data during routine operations. It then intercepts the master key while it momentarily resides in the computer’s memory in an unencrypted state. This approach circumvents the encryption by exploiting a transient state, effectively bypassing the protection without triggering any visible alerts.
Once the key is compromised, VoidStealer gains access to all saved passwords, session cookies, and other sensitive browser data. Session cookies are particularly dangerous in the hands of attackers, as they enable direct login to a victim’s accounts without needing a password, potentially leading to account hijacking, financial fraud, and identity theft.
VoidStealer’s Clever Encryption Bypass
VoidStealer executes its attack on the browser by employing a debugging technique. It attaches itself to the Chrome process as a debugger, a tool typically used by developers to inspect and control program execution. This allows the malware to monitor Chrome’s internal processes and halt its operation at a precise moment.
The malware sets a breakpoint at the exact instruction where Chrome decrypts its stored information. When Chrome reaches this point and the master key momentarily becomes readable in memory, the browser briefly pauses. VoidStealer then quickly extracts the key directly from memory before Chrome resumes normal operation, a process imperceptible to the user.
This sophisticated technique is not limited to Google Chrome; it also affects other browsers built on the Chromium engine, including Microsoft Edge, Brave, Opera, and Vivaldi. Any browser relying on Chrome’s App-Bound Encryption is potentially vulnerable, extending the scope of this threat far beyond just Chrome users.
Malware-as-a-Service Amplifies the Threat
The MaaS operational model behind VoidStealer significantly amplifies its danger compared to more targeted malware. It allows criminals lacking advanced technical skills to simply rent access to VoidStealer and deploy it against unsuspecting individuals. This lowers the entry barrier for launching cyberattacks and dramatically increases the pool of potential victims.
This situation underscores a broader challenge in browser security: malware developers are continually discovering new workarounds faster than browser vendors can implement effective patches, with everyday users bearing the brunt of these vulnerabilities. The continuous cat-and-mouse game between attackers and defenders demands constant vigilance and proactive security measures.
What You Should Do
- Use a Dedicated Password Manager: Avoid storing passwords and payment card details directly in your browser. A reputable, standalone password manager offers superior security.
- Exercise Caution with Downloads: Only download software from trusted, official sources. Infostealers are frequently bundled with pirated software, unofficial installers, or malicious attachments.
- Keep Software Updated: Regularly update your operating system, web browser, and all applications to ensure you have the latest security patches.
- Employ Robust Security Software: Run a reliable antivirus or endpoint detection and response (EDR) solution that provides real-time monitoring for suspicious activity.
- Enable Multi-Factor Authentication (MFA): Activate MFA on all critical accounts to add an extra layer of security, even if your password is stolen.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.