Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

Cybersecurity researchers have described a post-exploitation technique that allows an operator to access cookies, saved data, and authenticated browser sessions by enabling the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows.

The method does not entail taking advantage of a security flaw in Chrome or Edge, and it assumes that an operator already has code execution on the Windows host.

Compared to a remotely exploitable browser bug, the technique’s post-compromise situation is more limited due to the requirement for prior code execution and adequate access to alter the target process.

According to SpecterOps, defenders can use Sysmon Event IDs 8 and 10 to search for indications of process injection directed at chrome.exe and msedge.exe. In a March 2025 article, Google stated, “We’ve seen an increase in attackers using Chrome Remote Debugging to extract cookies since App-Bound Encryption was enabled.”

when seeing an uptick in attackers utilizing Chrome Remote Debugging to retrieve cookies when App-Bound Encryption (ABE) was introduced, Google modified Chrome’s remote debugging behavior starting with Chrome 136. According to the company, discussions about cookie theft thru the debugging read more about Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *