Filed under: Cybersecurity — Browser Security — August 2026

What happened

Security researchers publicly released a technique that lets malware already running on a Windows PC quietly switch on Chrome or Edge’s built-in debugging tools, then use them to grab every saved password, cookie, and logged-in session in the browser — without ever touching the encrypted password file. It works even though Google added a feature called “App-Bound Encryption” specifically to stop this kind of theft. There’s no CVE and no patch coming, because it’s not a software bug — it’s a way of misusing a legitimate browser feature. It only works if an attacker already has some form of malware running on the machine, so this is a research disclosure, not an active mass attack, though Google says it has already seen a rise in attackers using this style of trick.

Why it matters to your business

Plenty of Phoenix-area small businesses have staff who stay logged into email, banking, QuickBooks Online, or Microsoft 365 in Chrome or Edge all day, and let the browser save passwords for convenience. If one employee opens a malicious attachment or installs a fake tool, this technique means an attacker doesn’t just get that one file — they can walk out with every saved login and every active session, including ones that already passed an MFA prompt. That turns a single infected laptop into a master key for your accounting, email, and customer systems.

What to do this week

Confirm every PC is running Chrome 136 or later, or a current version of Edge — both now block the debugging switches this trick relies on unless the browser is launched in an unusual way, closing the easiest path in. Make sure you have real endpoint protection (EDR), not just basic antivirus, since stopping the initial malware infection is what actually prevents this. Ask your IT provider whether Chrome’s newer “Device Bound Session Credentials” feature (Chrome 146+) is turned on — it ties a login session to the specific PC so a stolen cookie is useless anywhere else. And discourage staff from saving banking or admin passwords in the browser itself; a dedicated password manager app is safer.

The bigger picture

This isn’t a single flaw that gets patched and disappears — it’s a reminder that no browser feature fully replaces keeping malware off the PC in the first place. — Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

Not sure your team’s endpoint protection would catch something like this? Book a free consult — https://micro1tech.com/contact/