Protecting Cookies with Device Bound Session Credentials

2026-04-10T07:23:47Z931533938dd8beb79c6dc2c3cdbbad41899130e328f2ab49fbe0fef166f6cdc1
AndroidAndroid 17ChromeDBSCDevice Bound Session CredentialsGeminiGenAIGoogle WorkspaceIPILLMLummaC2MTCMerkle Tree CertificatesPLANTS working group','Certificate Transparency','CT'PQCPost-Quantum CryptographyVRPVulnerability Rewards Programbug bountycookiesindirect prompt injectioninfostealerquantum-safe HTTPSsession hijackingsession theft

What happened

This batch of Google Security Blog posts covers multiple product security announcements and program updates: Chrome is rolling out Device Bound Session Credentials (DBSC) to Windows users in Chrome 146 (macOS support coming) to cryptographically bind session cookies to devices and prevent their misuse even if cookies are exfiltrated by infostealer malware; Google Workspace/GenAI teams describe a continuous, layered defense strategy against indirect prompt injection (IPI) targeting LLMs like Gemini; the Vulnerability Rewards Program (VRP) published its 2025 year-in-review; Android will begin PQ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
931533938dd8beb79c6dc2c3cdbbad41899130e328f2ab49fbe0fef166f6cdc1
Enrichment time
2026-04-10T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Protecting Cookies with Device Bound Session Credentials · Baitaphish