arstechnica.com 8/11/2026, 9:29:00 PM · external

Chrome adds device bound session credentials to stop cookie theft

Chrome adds device bound session credentials to stop cookie theft
CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE Chrome has introduced a new security feature called Device-Bound Session Credentials (DBSCs) that aims to combat account takeovers linked to session cookie theft. DBSCs store a unique encryption key in hardware secure elements such as the Trusted Platform Module (TPM) on Windows or secure enclaves on macOS and iOS. This prevents attackers from stealing session cookies and using them to impersonate legitimate users.

Only Chrome version 147 for Windows and 150 for macOS currently support DBSCs, and they are still in limited testing. This feature represents a shift from traditional shared-secret authentication methods toward more secure public key infrastructure, where servers rely on keys instead of easily stolen passwords.

View full article

Article by CyberSIXT