Protecting Cookies with Device Bound Session Credentials
2026-04-10T07:23:47Z•931533938dd8beb79c6dc2c3cdbbad41899130e328f2ab49fbe0fef166f6cdc1
AndroidAndroid 17ChromeDBSCDevice Bound Session CredentialsGeminiGenAIGoogle WorkspaceIPILLMLummaC2MTCMerkle Tree CertificatesPLANTS working group','Certificate Transparency','CT'PQCPost-Quantum CryptographyVRPVulnerability Rewards Programbug bountycookiesindirect prompt injectioninfostealerquantum-safe HTTPSsession hijackingsession theft
What happened
This batch of Google Security Blog posts covers multiple product security announcements and program updates: Chrome is rolling out Device Bound Session Credentials (DBSC) to Windows users in Chrome 146 (macOS support coming) to cryptographically bind session cookies to devices and prevent their misuse even if cookies are exfiltrated by infostealer malware; Google Workspace/GenAI teams describe a continuous, layered defense strategy against indirect prompt injection (IPI) targeting LLMs like Gemini; the Vulnerability Rewards Program (VRP) published its 2025 year-in-review; Android will begin PQ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 931533938dd8beb79c6dc2c3cdbbad41899130e328f2ab49fbe0fef166f6cdc1
- Enrichment time
- 2026-04-10T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.