Google has enabled a new security protection in Chrome for all Workspace users that prevents a common form of account takeover known as session cookie theft. The feature — Device Bound Session Credentials (DBSC) — is now active by default. No administrator action is required.
- What it is: DBSC cryptographically ties a user's browser session to their specific device using the device's security chip (such as a TPM on Windows). Even if malware steals a session cookie, the stolen token cannot be used on another device.
- Who is affected: All Google Workspace users accessing their accounts through Chrome on Windows. macOS support is rolling out in a future update.
- What the risk was: Stolen session cookies have been one of the most reliable ways attackers bypass multi-factor authentication — gaining access to Gmail, Drive, Calendar, and other Workspace apps without needing a password or MFA code.
- What to expect: No visible change for end users. Admins can monitor DBSC binding events in the Security Investigation Tool audit logs. The protection is on by default and cannot be disabled.
This is a meaningful improvement to Workspace account security, particularly for organisations concerned about phishing attacks that target session tokens rather than passwords. More information is available on the Google Workspace Blog.