← Back to Feed

Protecting Cookies with Device Bound Session Credentials

April 9, 2026 · Google Security Blog · Severity: LOW

Protecting Cookies with Device Bound Session Credentials. Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macO…. While lower severity, awareness and monitoring remain advisable to prevent potential escalation.

Key Takeaways

  • Credential theft and authentication bypass remain top attack vectors; MFA and passkeys improve security posture.
  • Medium severity threats still pose significant risk; organizations should prioritize detection and response controls.
  • Passwordless authentication and hardware security keys significantly reduce the risk of credential theft and account takeover.
☕ Buy a Coffee