Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero
To protect users from session cookie theft threats, Google has announced that it is launching Device Bound Session Credentials (DBSC), a security feature, in open beta.
First unveiled as a prototype in April 2024, DBSC is intended to connect authentication sessions to a device, preventing threat actors from accessing users' accounts and gaining illegal access from a different device under their control by using stolen cookies.
Andy Wen, senior director of product management at Google Workspace, stated that DBSC, which is accessible through the Chrome browser on Windows, helps bind a session cookie—small files that websites use to remember user information—to the device a user authenticated from and improves security after you are logged in.
The purpose of DBSC extends beyond post...

