Chrome Ships Device-Bound Session Credentials, Cryptographically Tying Sessions to the Machine That Made Them
Ars Technica·medium signal
Ars Technica calls DBSC possibly the best protection yet against session-token theft, the attack class that has quietly made MFA bypass routine. Stolen cookies become useless off the originating device because the session is bound to hardware-held keys. For anyone shipping agents or automation that reuses browser sessions, this changes the assumption that a copied cookie jar is portable.