Web_Logo
Remote Support
Google Workspace: New Feature Blocks Session Cookie Theft by Default
Home » Google Workspace Updates  »  Google Workspace: New Feature Blocks Session Cookie Theft by Default

Google Workspace: New Feature Blocks Session Cookie Theft by Default

Google has enabled a new security feature called Device Bound Session Credentials (DBSC) by default for all Google Workspace users on Chrome for Windows. This protects business accounts from a common attack method where cybercriminals steal browser session cookies to bypass passwords and multi-factor authentication entirely.

  • What it does: DBSC cryptographically ties your browser session to the specific device you authenticated from. Even if malware steals your session cookie, attackers cannot reuse it on a different device — breaking one of the most common account takeover techniques in use today.
  • No action required: The feature is automatically enabled for all Workspace customers, Individual subscribers, and personal Google accounts. Admins cannot disable it and there is nothing to configure.
  • Who benefits: All users signing in to Google Workspace through Chrome on Windows are now protected. macOS support using the device Secure Enclave is coming in a future Chrome release.
  • Admin visibility: Workspace administrators can monitor DBSC binding events through the Security Investigation Tool's audit logs, providing visibility into session integrity across the organisation.
  • Also rolling out this month: New iOS device management settings for Google Endpoint Management (now generally available) allow admins to harden security for both corporate-owned and BYOD iOS devices. Enhanced Data Loss Prevention (DLP) policies for third-party apps and Google Calendar are also in rollout.

This is a meaningful, automatic security improvement for any business using Google Workspace — particularly relevant given the increasing prevalence of infostealer malware targeting browser sessions. No action is needed, but IT managers should be aware the capability is now active.

Sources: Google Workspace Updates Blog | GBHackers | CybersecurityNews