Chrome 146 Adds Hardware-Bound Protection for Cookies
🔐 Google has introduced Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows to block infostealer malware from harvesting session cookies. The feature cryptographically ties session cookies to hardware-backed keys stored in the Trusted Platform Module (TPM) on Windows, with macOS support planned for a future release. Because the per-session private keys are generated by a security chip and cannot be exported, exfiltrated cookies become useless without proof of key possession. The protocol is privacy-conscious, uses distinct keys per session to avoid cross-site correlation, and was developed with industry input including Microsoft.
