Google Chrome Unveils New Protection Against Session Cookie Theft
In a proactive move to enhance user security, Google has introduced Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows. This feature aims to thwart info-stealing malware that targets session cookies, which are often exploited by hackers to gain unauthorized access to user accounts.
The DBSC protocol links session credentials to specific hardware components, such as the Trusted Platform Module (TPM) on Windows, ensuring that stolen cookies cannot be used by attackers. This innovation is set to roll out for macOS users in a future update.
Affected users include anyone utilizing Chrome for Windows, especially those concerned about credential theft. The impact is significant, as it reduces the effectiveness of sophisticated malware like LummaC2, which has been known to harvest session cookies.
To protect oneself, users should keep Chrome updated and remain vigilant against suspicious downloads.
Risk Level: Medium
Source: View Original Report
