Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server. Infostealer malware families, such as LummaC2, have become increasingly sophisticated at harvesting these credentials.

DBSC protects against session theft by cryptographically binding authentication sessions to a specific device. It shifts the paradigm from reactive detection to proactive prevention, ensuring that successfully exfiltrated cookies cannot be used to access users’ accounts. The feature is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release.