Chrome stops hackers from stealing your browser cookies now - how its new security feature works
Chrome is rolling out DBSC on Windows and Mac to bind session cookies to a device chip, making stolen cookies harder to reuse.
Intelligence analysis by GPT-5.4 Mini
Google is turning on Device Bound Session Credentials in Chrome so session cookies stay tied to the device that created them. That makes cookie theft less useful for attackers who try to log in from another machine.
Browser cookies are like tiny sticky notes that help a website remember a person after they log in. Hackers sometimes steal those notes and try to use them on their own computer.
Chrome's new trick locks those notes to the original computer. It is a bit like a key that only works in one lock, even if someone copies the shape of it.
That means stolen cookies are much less useful. The browser still needs to be updated, but once it is, Chrome tries to make cookie theft a lot harder.
Analysis
What changed
Google is rolling out Device Bound Session Credentials, or DBSC, in Chrome as an anti-theft layer for browser sessions. The feature is designed to make stolen cookies less useful by binding them to the device where the session was created instead of leaving them portable.
How it works
In a typical cookie-hijacking attack, malware can steal browser cookies and the data inside them, then reuse those cookies on another device to sign in as the victim. DBSC changes that by linking the browser session to the computer's security hardware. On most Windows PCs, that is the Trusted Platform Module; on Macs, it is the Secure Enclave. If an attacker copies the cookies, they are still tied to the original device and cannot simply be replayed elsewhere.
Google says the feature strengthens account security after login and makes session theft meaningfully harder, even if malware is present on the user's device. The company first started developing DBSC in 2024, then opened it to Google Workspace customers in 2025. The new part is that it is now enabled by default for all Google Workspace and personal Google accounts in Chrome for Windows, with Mac support also described in the rollout. Users do not need to flip a setting; they just need to be on a recent Chrome version, with Google pointing to Chrome 146 or later on Windows and 148 or later on Mac. The browser updates through the About Google Chrome menu and takes effect after a restart.
Key points
- Chrome is rolling out Device Bound Session Credentials to fight cookie-hijacking attacks.
- The feature ties session cookies to device hardware such as TPM on Windows and Secure Enclave on Mac.
- Google says the protection is enabled by default for Google Workspace and personal Google accounts.
- Users need recent Chrome versions and must restart the browser after updating.
If DBSC works as intended, it can make stolen session cookies much less valuable to attackers. Automatic default protection also lowers the burden on users and admins who would otherwise need to turn the feature on manually.
The feature does not stop every browser attack; it mainly reduces the payoff from stolen cookies after login. Users who are not on the required Chrome versions will not get the protection, and malware on a device can still be a broader security problem.



