Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Researchers have discovered a post-exploitation technique leveraging Chrome DevTools Protocol (CDP) to steal cookies and sensitive data from running instances of Chrome and Edge on Windows. This method bypasses standard browser protections, such as Device Bound Session Credentials, and allows attackers to gain full control over the browser's session and user data. The technique relies on injecting CDP into a running browser process and uses a publicly available toolkit to extract cookies, browser history, saved passwords, and other sensitive information. This follows a similar technique targeting macOS with AmnesiaStealer, which also uses CDP to control a Chromium browser.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
