
Chrome adds hardware-backed session keys to curb account takeovers
Google Chrome is adding device-bound session credentials (DBSCs) that store a private key in hardware (TPM on Windows, Secure Enclave on macOS/iOS) to sign authentication challenges, making stolen session cookies useless for account takeover. Currently limited to a test rollout on Windows and macOS, the feature aims to reduce reliance on shared secrets and work alongside passkeys and 2FA; other Chromium-based browsers may adopt it as the standard progresses via the W3C.

