CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

Chrome adopts what may be the best protection yet against account takeovers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4264

As cited

Copy frozen at (site build).

identity access

Chrome adopts what may be the best protection yet against account takeovers

Google Chrome has introduced device-bound session credentials (DBSCs), a new security feature that stores encryption keys in hardware security modules built into devices, such as Trusted Platform Modules (TPMs) on Windows or secure enclaves on macOS and iOS. This approach protects against session cookie theft, a growing vector for account takeovers that circumvents two-factor authentication and passkey defenses. Recent versions of Chrome for Windows and macOS now generate and protect these keys automatically.

Why it matters: Organizations and individual users relying on Chrome should understand that this feature reduces the risk of account compromise from stolen session cookies, which attackers increasingly target when multi-factor authentication is in place. Practitioners should monitor adoption and evaluate whether the hardware requirements (functional TPM or secure enclave) cover their user base.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Chrome adopts what may be the best protection yet against account takeovers

Google Chrome has introduced device-bound session credentials (DBSCs), a new security feature that stores encryption keys in hardware security modules built into devices, such as Trusted Platform Modules (TPMs) on Windows or secure enclaves on macOS and iOS. This approach protects against session cookie theft, a growing vector for account takeovers that circumvents two-factor authentication and passkey defenses. Recent versions of Chrome for Windows and macOS now generate and protect these keys automatically.

Why it matters: Organizations and individual users relying on Chrome should understand that this feature reduces the risk of account compromise from stolen session cookies, which attackers increasingly target when multi-factor authentication is in place. Practitioners should monitor adoption and evaluate whether the hardware requirements (functional TPM or secure enclave) cover their user base.

VendorsMicrosoftAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary