Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero
Jul 30, 2025
Device Security / AI Security
 Google has announced that it's making available a security feature called Device Bound Session Credentials (DBSC)  in open beta to ensure that users are safeguarded against session cookie theft attacks.  DBSC, first introduced  as a prototype in April 2024, is designed to bind authentication sessions to a device so as to prevent threat actors from using stolen cookies to sign-in to victims' accounts and gain unauthorized access from a separate device under their control.  "Available in the Chrome browser on Windows, DBSC strengthens security after you are logged in and helps bind a session cookie – small files used by websites to remember user information – to the device a user authenticated from," Andy Wen, senior director of product management at Google Workspace, said .  DBSC is not only meant to secure user accounts post-authentication. It makes it a lot more difficult for bad actors to reuse session cookies and improves session integrity.   The company also note...