Brief
Chrome's Device Bound Session Credentials enters public availability for Windows
Device Bound Session Credentials (DBSC) is now publicly available for Windows users on Chrome 146, with macOS support planned in an upcoming release. The feature aims to prevent stolen session cookies from being used to access accounts.
Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server. Infostealer malware families, such as LummaC2, have become increasingly sophisticated at harvesting these credentials.
DBSC protects against session theft by cryptographically binding authentication sessions to a specific device. It shifts the paradigm from reactive detection to proactive prevention, ensuring that successfully exfiltrated cookies cannot be used to access users’ accounts. The feature is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release.
Our reading
For small teams, this browser-level protection could reduce the risk from credential-stealing malware, but its effectiveness depends on users running supported Chrome versions and the feature's rollout.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by security.googleblog.com
- Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146.
- DBSC is expanding to macOS in an upcoming Chrome release.
- DBSC protects against session theft by cryptographically binding authentication sessions to a specific device.
- Session theft typically occurs when a user inadvertently downloads malware onto their device.
- Infostealer malware families, such as LummaC2, have become increasingly sophisticated at harvesting these credentials.
- There is no reliable way to prevent cookie exfiltration using software alone on any operating system.
- DBSC shifts the paradigm from reactive detection to proactive prevention, ensuring that successfully exfiltrated cookies cannot be used to access users’ accounts.
Sources
- Google Online Security BlogText stored 16 September 2026
How this story was checked. Written from the 1 page listed above, stored 16 September 2026; claims checked against that stored text on 16 September 2026.
What that means
- 7 of 7 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief