:

CHROME ROLLS OUT SESSION COOKIE THEFT PROTECTION

INDUSTRY DESK2 MIN READ
FRI, MAY 29, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

Google Chrome now offers Device Bound Session Credentials (DBSC) protection to its entire user base. The security feature, which has reached general availability, binds session cookies to individual devices, making stolen credentials useless if accessed from another computer or device. ■ How It Works DBSC ties session cookies to a device's hardware keys, ensuring that even if an attacker obtains a cookie through phishing, malware, or network interception, they cannot use it to access accounts from a different device. This adds a critical layer of protection beyond traditional cookie security. ■ Broader Protection The rollout applies to users across all platforms where Chrome operates. Google designed DBSC to defend against a common attack vector: session hijacking, where cybercriminals gain access to active user sessions without needing passwords. This approach proves especially valuable for high-value targets, including enterprise users and individuals managing sensitive accounts. The feature works behind the scenes, requiring no user configuration or action to enable. ■ Industry Context Session cookie theft remains a significant security concern. Attackers frequently exploit compromised cookies to bypass multi-factor authentication and gain direct account access. DBSC addresses this vulnerability at the browser level, offering protection regardless of whether websites implement additional security measures. Google has worked with industry partners on the DBSC standard, positioning it as a potential foundation for broader web security improvements. ■ Availability The rollout is gradual, meaning not all users will see the feature simultaneously. Chrome users should expect full deployment in coming weeks. The feature operates automatically once enabled on compatible systems.

■ SOURCES

Bleeping ComputerEngadgetArs TechnicaBleeping ComputerEngadget

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.

2H AGOSecurity Desk

A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.

2H AGOIndustry Desk

McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.

2H AGOAI Desk

Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.

5H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.