
Account Takeover Without Breaking Two-Factor Authentication: The Session-Theft Loophole Chrome Just Closed
Google Chrome's DBSC locks the private key generated at login inside the TPM or Secure Enclave, rendering stolen session cookies useless. The Windows rollout began in April, and phased deployment to Workspace started in May, but older PCs without TPM and users of other browsers remain outside the protection.








