Generic CC0 editorial illustration

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attack…

Editorial note. This page preserves feed metadata and a bounded excerpt for discovery. It does not reproduce the publisher's complete article.

Open the complete publication at Google Security Blog →

Record details

  • Local record: b51c31027c63779f693c
  • Source feed: Google Security Blog
  • Published: 2026-04-09T17:07:00Z