Protecting Cookies with Device Bound Session Credentials

2026-04-10T13:23:45Z263a9a4c1e20ea557040523fce006960ed1383d37cb4f0ccf6af2375af94926b
AndroidAndroid 17Chrome 146DBSCDevice Bound Session CredentialsGenAI securityGoogle WorkspaceLLM securityLummaC2MTCMerkle Tree CertificatesNIST PQCPLANTS working group','Certificate Transparency','quantum-safe-#PQCVRP 2025Vulnerability Rewards ProgramWindowscookie theftindirect prompt injectioninfostealermacOSpost-quantum cryptographyproactive preventionprompt injectionsession hijacking

What happened

This collection of Google Security Blog posts (Apr–Feb 2026) announces multiple defensive and platform-security advances: Device Bound Session Credentials (DBSC) are publicly available on Windows in Chrome 146 (macOS coming) to prevent stolen browser cookies from being reused by tying session tokens to a device and shifting from reactive detection to proactive prevention against infostealer malware (e.g., LummaC2). Google Workspace/GenAI teams describe a continuous, multi-layered approach to mitigate indirect prompt injection (IPI) risks against LLMs and agentic automation. The Vulnerability R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
263a9a4c1e20ea557040523fce006960ed1383d37cb4f0ccf6af2375af94926b
Enrichment time
2026-04-10T13:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.