Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Enhances Chrome Security with Device-Bound Sessions

Google Enhances Chrome Security with Device-Bound Sessions

Posted on April 11, 2026 By CWS

Google has taken a significant step forward in enhancing browser security with the introduction of Device Bound Session Credentials (DBSC) for Chrome users on Windows. This development, announced by the Google Account Security and Chrome teams, aims to prevent session hijacking—a common method used by attackers to gain unauthorized access to user accounts.

Strengthening Security Measures

The new feature is expected to roll out to macOS soon, representing a shift from reactive threat detection to proactive prevention in the industry. Traditionally, session theft occurs when a user inadvertently downloads malware like the LummaC2 family, which scans the browser’s stored session cookies. These cookies can be exploited by threat actors to bypass authentication processes.

Historically, preventing malware from accessing browser memory through software alone has been challenging. Security teams have often had to rely on post-breach detection methods. However, the introduction of DBSC aims to change this dynamic by tying authentication sessions directly to a user’s physical device, using hardware-backed security measures.

How DBSC Works

DBSC uses hardware security modules such as the Trusted Platform Module (TPM) or Secure Enclave to generate a unique public-private key pair during login. The private key remains securely stored on the device and cannot be accessed externally. Websites supporting DBSC issue short-lived cookies, requiring Chrome to continually validate its possession of the private key.

This approach renders stolen session cookies ineffective, as they expire quickly without the associated hardware key. The integration of DBSC is designed to be seamless for developers, with Chrome managing the cryptographic processes in the background.

Privacy and Future Developments

Despite its robust security capabilities, DBSC is built with privacy in mind. Each session uses a separate key, ensuring that websites cannot track users across different sites or correlate their browsing habits. This minimizes the potential for device fingerprinting while maintaining security.

Google worked alongside the W3C Web Application Security Working Group and partners like Microsoft to develop DBSC as an open web standard. The company plans to broaden DBSC’s application to safeguard federated identity and Single Sign-On (SSO) environments. Additionally, efforts are underway to enhance registration options with existing hardware security keys and explore software-based key support for devices lacking physical security hardware.

Stay informed with the latest cybersecurity updates by following us on Google News, LinkedIn, and X. Contact us to share your stories.

Cyber Security News Tags:Chrome, cookie theft, Cybersecurity, DBSC, device-bound sessions, Google, macOS, Security, Technology, Windows

Post navigation

Previous Post: Law Enforcement’s Use of Webloc for Global Device Tracking
Next Post: Google Enhances Gmail with Mobile End-to-End Encryption

Related Posts

Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide Cyber Security News
VINclarity Faces Coordinated Online Reputation Assault VINclarity Faces Coordinated Online Reputation Assault Cyber Security News
DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools Cyber Security News
Massive Android Ad Fraud Uncovered with 455 Apps Massive Android Ad Fraud Uncovered with 455 Apps Cyber Security News
Security Issues Found in Popular Android VPN Apps Security Issues Found in Popular Android VPN Apps Cyber Security News
GolangGhost Malware Targets Crypto Professionals GolangGhost Malware Targets Crypto Professionals Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions
  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions
  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark