Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

VoidStealer, an infostealer trojan, has implemented a working bypass of Google Chrome’s App-Bound Encryption (ABE), a credential-protection control introduced in Chrome 127 (mid-2024). The bypass allows attackers to extract saved passwords and session cookies from Chrome without triggering ABE’s process-binding defenses, effectively neutralizing a control many organizations rely on to protect browser-stored credentials. Any workforce using Chrome with saved credentials or active sessions is at elevated risk of credential theft and session hijacking, regardless of whether ABE was considered part of their browser security posture.

Author

Tech Jacks Solutions