Google’s New Chrome Security Feature Blocks Cookie Theft Attacks – DBSC Open Beta Now Available


# Google Strengthens Cybersecurity with New Anti-Theft Features and Transparency Measures

Google has launched several significant security initiatives aimed at protecting users from cyber threats and improving vulnerability disclosure processes.

## Device Bound Session Credentials Combat Cookie Theft

Google has released Device Bound Session Credentials (DBSC) in open beta, a security feature designed to prevent session cookie theft attacks. Originally introduced as a prototype in April 2024, DBSC binds user authentication sessions directly to their devices, making it nearly impossible for cybercriminals to use stolen cookies to access accounts from different devices.

Currently available on Chrome for Windows, DBSC strengthens post-login security by tying session cookies—small files that websites use to remember user information—to the specific device where authentication occurred. This significantly reduces the risk of unauthorized account access and improves overall session integrity.

“DBSC strengthens security after you are logged in and helps bind a session cookie to the device a user authenticated from,” explained Andy Wen, senior director of product management at Google Workspace.

## Enhanced Authentication Options

Google has also expanded its security offerings by making passkey support generally available to over 11 million Google Workspace customers. The update includes enhanced administrative controls that allow organizations to audit enrollment and restrict passkeys to physical security keys for added protection.

Additionally, Google plans to introduce a shared signals framework (SSF) receiver in closed beta for select customers. This system will enable real-time exchange of critical security information using OpenID standards, allowing organizations to coordinate responses to security threats more effectively.

## Project Zero Introduces Reporting Transparency

Google’s Project Zero security team has announced a new “Reporting Transparency” policy to address the upstream patch gap—the delay between when security fixes become available from vendors and when they reach end users through downstream products.

Under this new approach, Project Zero will publicly disclose vulnerability discoveries within one week of reporting them to affected vendors. The disclosure will include:

– The vendor or open-source project involved
– The affected product
– The report filing date
– The 90-day disclosure deadline

“The primary goal of this trial is to shrink the upstream patch gap by increasing transparency,” said Project Zero’s Tim Willis. “By providing an early signal that a vulnerability has been reported upstream, we can better inform downstream dependents.”

## AI-Powered Vulnerability Detection

Google plans to extend this transparency principle to Big Sleep, an AI-powered vulnerability discovery tool developed through collaboration between DeepMind and Google Project Zero. The system uses artificial intelligence to identify security flaws more efficiently than traditional methods.

Importantly, Google emphasizes that no technical details, proof-of-concept code, or information that could assist malicious actors will be released until the standard 90-day disclosure deadline expires.

These initiatives represent Google’s comprehensive approach to cybersecurity, combining proactive threat prevention with improved industry-wide vulnerability disclosure practices to create a more secure digital ecosystem for all users.

Share This Article