CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4518

As cited

Copy frozen at (site build).

threat intel

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

Researchers disclosed a post-exploitation technique that leverages the Chrome DevTools Protocol (CDP) to extract cookies, saved data, and authenticated sessions from running Chrome or Edge processes on Windows. The attack requires pre-existing code execution on the target host and allows operators to hijack active browser sessions.

Why it matters: Windows administrators and security teams need to understand that code execution on endpoints can lead to session theft from major browsers; incident responders should monitor for unusual CDP access patterns when investigating compromised systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

Researchers disclosed a post-exploitation technique that leverages the Chrome DevTools Protocol (CDP) to extract cookies, saved data, and authenticated sessions from running Chrome or Edge processes on Windows. The attack requires pre-existing code execution on the target host and allows operators to hijack active browser sessions.

Why it matters: Windows administrators and security teams need to understand that code execution on endpoints can lead to session theft from major browsers; incident responders should monitor for unusual CDP access patterns when investigating compromised systems.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary