Google has added a feature to Chrome called " Device Bound Session Credentials ," which ties cookies to a specific device , preventing hackers from stealing and using them to compromise accounts.

Cookies are files that websites use to remember users' information and browsing preferences and automatically log them into a service or website. These cookies are created after you log in to a service and verify with multi-factor authentication (MFA). So, on future logins, cookies can bypass (MFA) and that's why hackers "hunt" them.
Often, they use malware to steal cookiesand compromise connected accounts.
See also: PayPal: Strengthening account security by detecting stolen super-cookies
To solve this problem, Google is bringing the “Device Bound Session Credentials” (DBSC) feature to Chrome, which makes it impossible for attackers to steal your cookies. After enabling DBSC, the authentication process is tied to a specific new public/private key pair generated using your device’s Trusted Platform Module (TPM) chip, which cannot be exported and is stored securely on your device. This way, even if hackers steal cookies, they won’t be able to access your accounts.
“ We believe this will significantly reduce the success rate of cookie-stealing malware . Attackers will be forced to act locally on the device, which makes detection and cleanup on the device more effective ,” a Google engineer said
See also: How to enable or disable cookies in Google Chrome
The feature is still in the prototype phase, but you can try out DBSC by going to chrome://flags/ and enabling the “enable-bound-session-credentials” flag in Windows, Linux, and macOS Chromium-based web browsers.
“Device Bound Session Credentials” allows a server to start a new session with your browser and associate it with a public key stored on your device, using a dedicated API. Each session is backed by a unique key to protect privacy , with the server only receiving the public key used to verify ownership later. DBSC prevents websites from tracking you across different sessions on the same device, and you can delete the keys it generates at any time.

"When fully deployed, consumers and enterprise users will automatically receive upgraded security for their Google accounts," the company said.
“We are also working to bring this technology to our Google Workspace and Google Cloud customers so they have another layer of account security“.
See also: Google: Fixed two zero-day vulnerabilities in Chrome
Google Chrome's new 'Device Bound Session Credentials' security feature significantly enhances user security. It will effectively block the misuse of stolen cookies, as hackers will not have access to the cryptographic keys required to use them. This means that even if a hacker manages to steal a user's cookies, they will not be able to use them to compromise account unless they have access to the device itself.
Additionally, the new security feature may encourage users to browse in incognito mode more often, as cookies are not stored after the session is closed. This may also help protect user.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, it is important to note that although the new security feature offers additional protection, users should continue to be vigilant with the security of their devices, regularly update software, and implement security best practices.
Source: www.bleepingcomputer.com
