Threat Intelligence

New Attack Technique Lets Hackers Hijack Your Logged-In Browser Sessions

The Hacker News · 14 Aug 2026
Key Takeaway Keep endpoint security software up to date and train staff to recognise phishing attempts, since preventing initial device compromise is the best defence against this kind of session hijacking.

Cybersecurity researchers have uncovered a technique that allows attackers to enable a hidden browser feature called the Chrome DevTools Protocol (CDP) inside a running Chrome or Edge process on Windows. Once activated, this gives an attacker access to cookies, saved data, and any currently logged-in accounts within that browser session—effectively letting them impersonate the user without needing a password.

Importantly, this technique requires the attacker to already have some level of code execution on the victim's Windows computer, typically achieved through malware, a phishing attack, or another initial compromise. It's a 'post-exploitation' method, meaning it's used to expand access and steal data after a system has already been breached, rather than being the initial point of entry.

While this technique doesn't create a new way in, it highlights how attackers can quietly hijack active browser sessions—bypassing multi-factor authentication protections that only apply at login—once they've gained a foothold on a device. For small businesses, this reinforces the importance of stopping the initial infection before it happens, since browser session theft can occur silently in the background.

browser security session hijacking Windows security Chrome post-exploitation

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.