Chrome adds device-bound session credentials to block cookie theft account takeovers
Google Chrome has rolled out device-bound session credentials (DBSCs), a new security feature that stores a unique encryption key inside a hardware security module built into the device — a TPM on Windows, a secure enclave on macOS and iOS. The feature protects against session cookie theft, a growing attack method that bypasses two-factor authentication and passkeys. DBSC is now active in recently released versions of Chrome for Windows and macOS.
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!