Chrome adopts what may be the best protection yet against account takeovers

Google Chrome has introduced Device-Bound Session Credentials (DBSC) to prevent session cookie theft, a common method used in account takeovers. This security feature binds session keys to the hardware of the user's device, such as a TPM or secure enclave.
Why it matters
As traditional phishing becomes less effective due to multi-factor authentication, this technology addresses the growing threat of infostealer malware targeting active browser sessions.
NEW FROM CHROME Chrome adopts what may be the best protection yet against account takeovers Device-bound session credentials thwart an increasingly common form of account takeover.
12 Credit: Getty Images Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in