Google has rolled out a significant new security feature to all Google Workspace users that makes it substantially harder for attackers to hijack accounts — even if they manage to steal a user's session cookie.
- What it is: Device Bound Session Credentials (DBSC) is a new capability in Chrome that cryptographically ties your Google login session to your specific device, using the TPM chip on Windows (or Secure Enclave on macOS). Even if an attacker steals your session cookie, they cannot use it from a different computer.
- Who is affected: All Google Workspace users on Chrome for Windows (Chrome 146 or later). This feature is on by default — no configuration or IT action is required.
- What risk it addresses: Session cookie theft is one of the most common account takeover methods, and it can bypass multi-factor authentication (MFA). DBSC directly closes this attack path by making stolen cookies useless on any other device.
- What action is needed: None required for end users. Admins can monitor DBSC binding events in the Google Workspace security investigation tool. Ensure staff are running an up-to-date version of Chrome.
This rollout began on 3 June 2026 and will reach all Workspace tenants progressively within 60 days. It is a positive development that requires no changes to existing policies or workflows. More detail is available from the Google Workspace Updates blog.