New Attack Technique Lets Hackers Hijack Your Logged-In Browser Sessions
Cybersecurity researchers have uncovered a technique that allows attackers to enable a hidden browser feature called the Chrome DevTools Protocol (CDP) inside a running Chrome or Edge process on Windows. Once activated, this gives an attacker access to cookies, saved data, and any currently logged-in accounts within that browser session—effectively letting them impersonate the user without needing a password.
Importantly, this technique requires the attacker to already have some level of code execution on the victim's Windows computer, typically achieved through malware, a phishing attack, or another initial compromise. It's a 'post-exploitation' method, meaning it's used to expand access and steal data after a system has already been breached, rather than being the initial point of entry.
While this technique doesn't create a new way in, it highlights how attackers can quietly hijack active browser sessions—bypassing multi-factor authentication protections that only apply at login—once they've gained a foothold on a device. For small businesses, this reinforces the importance of stopping the initial infection before it happens, since browser session theft can occur silently in the background.