As cited
Copy frozen at (site build).
identity access
Chrome adopts what may be the best protection yet against account takeovers
Google Chrome has introduced device-bound session credentials (DBSCs), a new security feature that stores encryption keys in hardware security modules built into devices, such as Trusted Platform Modules (TPMs) on Windows or secure enclaves on macOS and iOS. This approach protects against session cookie theft, a growing vector for account takeovers that circumvents two-factor authentication and passkey defenses. Recent versions of Chrome for Windows and macOS now generate and protect these keys automatically.
Why it matters: Organizations and individual users relying on Chrome should understand that this feature reduces the risk of account compromise from stolen session cookies, which attackers increasingly target when multi-factor authentication is in place. Practitioners should monitor adoption and evaluate whether the hardware requirements (functional TPM or secure enclave) cover their user base.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
identity access
Chrome adopts what may be the best protection yet against account takeovers
Google Chrome has introduced device-bound session credentials (DBSCs), a new security feature that stores encryption keys in hardware security modules built into devices, such as Trusted Platform Modules (TPMs) on Windows or secure enclaves on macOS and iOS. This approach protects against session cookie theft, a growing vector for account takeovers that circumvents two-factor authentication and passkey defenses. Recent versions of Chrome for Windows and macOS now generate and protect these keys automatically.
Why it matters: Organizations and individual users relying on Chrome should understand that this feature reduces the risk of account compromise from stolen session cookies, which attackers increasingly target when multi-factor authentication is in place. Practitioners should monitor adoption and evaluate whether the hardware requirements (functional TPM or secure enclave) cover their user base.
- Source published
- First seen by Cybersecurity Tracker