Google has enabled a new security feature called Device Bound Session Credentials (DBSC) by default for all Google Workspace users on Chrome for Windows. This protects business accounts from a common attack method where cybercriminals steal browser session cookies to bypass passwords and multi-factor authentication entirely.
- What it does: DBSC cryptographically ties your browser session to the specific device you authenticated from. Even if malware steals your session cookie, attackers cannot reuse it on a different device — breaking one of the most common account takeover techniques in use today.
- No action required: The feature is automatically enabled for all Workspace customers, Individual subscribers, and personal Google accounts. Admins cannot disable it and there is nothing to configure.
- Who benefits: All users signing in to Google Workspace through Chrome on Windows are now protected. macOS support using the device Secure Enclave is coming in a future Chrome release.
- Admin visibility: Workspace administrators can monitor DBSC binding events through the Security Investigation Tool's audit logs, providing visibility into session integrity across the organisation.
- Also rolling out this month: New iOS device management settings for Google Endpoint Management (now generally available) allow admins to harden security for both corporate-owned and BYOD iOS devices. Enhanced Data Loss Prevention (DLP) policies for third-party apps and Google Calendar are also in rollout.
This is a meaningful, automatic security improvement for any business using Google Workspace — particularly relevant given the increasing prevalence of infostealer malware targeting browser sessions. No action is needed, but IT managers should be aware the capability is now active.
Sources: Google Workspace Updates Blog | GBHackers | CybersecurityNews