Google Chrome adds session cookie theft protection for all users

2026-05-29T13:23:34Z720c86e1865582662723fec3da3b61c771a35b80693b663d65ff816d2fbc577e
ai-generated-luresai-model-securityandroid-ratanthropic-mythosauthentication-bypassbtmobcarnival-corporationcharter-communicationschrome-dbsccve-2026-35616data-breachdevice-bound-session-credentialsekz-infostealerfbififa-fraudforticlient-emsgogs-zero-daygreyvibepersonal-data-theftphishing-builderpolymarket-insider-tradingrcesession-cookie-theftshinyhunterssiem-msps

What happened

A roundup of security news: Google Chrome has enabled Device Bound Session Credentials (DBSC) broadly to mitigate session-cookie theft and account takeovers. Multiple large data breaches and extortion incidents tied to the ShinyHunters gang affect major victims (Charter ~4.9M accounts, Carnival ~6M). A North Carolina man was sentenced over selling data on 7M elderly Americans; other legal actions include sentences for a Romanian hacker and a sextortionist, and a Google engineer charged with Polymarket insider trading. Active threats and vulnerabilities include exploitation of an authentication

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
720c86e1865582662723fec3da3b61c771a35b80693b663d65ff816d2fbc577e
Enrichment time
2026-05-29T13:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google Chrome adds session cookie theft protection for all users · Baitaphish