Apr 10, 2026 • [email protected] (The Hacker News)
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Google has made Device Bound Session Credentials (DBSC) generally available in Chrome 146 for all Windows users, representing a significant security...
Executive Summary
Google has made Device Bound Session Credentials (DBSC) generally available in Chrome 146 for all Windows users, representing a significant security enhancement to protect against session theft attacks. The feature, previously tested in open beta, binds user sessions directly to the device, making it significantly more difficult for attackers to hijack authenticated sessions. The rollout is currently limited to Windows users, with macOS support planned for a future Chrome release. DBSC aims to combat credential theft techniques that leverage browser session cookies, providing a more robust authentication mechanism by ensuring session validity is tied to the specific device used during login.
Summary
Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. "This project represents a significant
Published Analysis
Google has made Device Bound Session Credentials (DBSC) generally available in Chrome 146 for all Windows users, representing a significant security enhancement to protect against session theft attacks. The feature, previously tested in open beta, binds user sessions directly to the device, making it significantly more difficult for attackers to hijack authenticated sessions. The rollout is currently limited to Windows users, with macOS support planned for a future Chrome release. DBSC aims to combat credential theft techniques that leverage browser session cookies, providing a more robust authentication mechanism by ensuring session validity is tied to the specific device used during login. Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. "This project represents a significant Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. "This project represents a significant