Yet Another Way to Bypass Google Chrome's Encryption Protection

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Authors of the VoidStealer Trojan have found a new method to bypass Google Chrome's App-Bound Encryption (ABE), a security feature introduced in July 2024 to protect session cookies and credentials from infostealers on Windows. Unlike previous bypasses that required privilege escalation or code injection, VoidStealer attaches to Chrome as a debugger, pauses execution at the exact moment Chrome decrypts data and exposes the master key in plaintext memory, then extracts the key directly. This is the latest in a series of successful ABE bypasses by various infostealer families including Meduza Stealer, Lumma Stealer, and others, highlighting that browsers remain a high-value target as enterprises store increasing amounts of sensitive data in web applications.

4m read timeFrom darkreading.com
Post cover image
Table of contents
Bypassing Browser ProtectionsA Different Tactic

Sort: