Google Chrome Enhances Security with App-Bound Encryption in Version 127

01 Aug 2024

Google Chrome has taken a significant step forward in enhancing cookie protection on Windows systems by introducing app-bound encryption, a feature designed to bolster defenses against information-stealing malware attacks. In a recent blog post, Chrome software engineer Will Harris elaborated on the advancements made in Chrome’s security protocols.

Enhanced Security Measures

Currently, Chrome leverages the most robust techniques available on various operating systems to protect sensitive data, including cookies and passwords. For instance, macOS utilizes Keychain services, while Linux employs kwallet or gnome-libsecret. On Windows, the Data Protection API (DPAPI) serves as the primary safeguard. However, Harris pointed out a critical limitation of DPAPI: while it effectively protects data at rest from cold boot attacks and unauthorized users, it does not defend against malicious tools or scripts that execute code as the logged-in user—an avenue frequently exploited by infostealer malware.

In response to this vulnerability, Harris announced the introduction of Application-Bound (App-Bound) Encryption in Chrome 127 for Windows. This new protection mechanism enhances the capabilities of DPAPI by tying encrypted data to the identity of the application requesting it. This approach mirrors the functionality of Keychain on macOS, ensuring that only the intended application can access the encrypted data.

Chrome’s App-Bound Encryption operates through a new Windows service running under ‘SYSTEM’ privileges, which verifies an application’s identity when it seeks encryption. By encoding the app’s identity into the encrypted data, the system effectively prevents unauthorized applications from decrypting it. As a result, any attempt by other apps to access this data will fail, thereby increasing the difficulty for attackers who would need to gain system privileges or inject code into Chrome—actions that are typically outside the realm of legitimate behavior and easier for antivirus software to detect.

This enhanced protection will extend beyond cookies to include passwords, payment data, and other persistent authentication tokens, further fortifying user defenses against infostealer malware. This initiative complements other recent security measures introduced by Google, such as Chrome’s download protection utilizing Safe Browsing, Device Bound Session Credentials, and account-based threat detection aimed at identifying the use of stolen cookies.

Harris emphasized the broader implications of App-Bound Encryption, stating that it raises the cost of data theft for attackers while simultaneously making their activities more conspicuous on the system. “It helps defenders draw a clear line in the sand for what is acceptable behavior for other apps on the system,” he noted.

As the landscape of malware continues to evolve, Google remains committed to collaborating with the security community to enhance detection capabilities and strengthen operating system protections, including the development of more robust app isolation primitives to address potential bypasses.

In addition to these advancements, Google recently rolled out new warnings in Chrome for downloading password-protected archives and improved alerts that provide users with more detailed information about potentially malicious downloaded files.

How to sign in google account on chrome?

To sign in to your Google account on Chrome, follow these steps: 1. Open Chrome and click on the three vertical dots at the top-right corner. 2. Select 'Settings'. 3. Click on 'Sign in to Chrome' at the top of the page. 4. Enter your Google account email and click 'Next'. 5. Enter your password and click 'Next' again. 6. Follow any additional prompts, such as two-factor authentication, to complete the sign-in process. You will now be signed in to your Google account on Chrome.

How to block pop-ups on google chrome?

To block pop-ups on Google Chrome, follow these steps: 1. Open Chrome and click on the three vertical dots at the top-right corner. 2. Select 'Settings'. 3. Scroll down and click on 'Privacy and security' in the left-hand menu. 4. Click on 'Site Settings'. 5. Under 'Content', click on 'Pop-ups and redirects'. 6. Toggle the switch to 'Blocked (recommended)'. This will block most pop-ups from appearing. For specific websites, you can add exceptions by clicking 'Add' next to 'Allow'.
Google Chrome

Google Chrome download for free to PC or mobile

Latest update Google Chrome download for free for Windows PC or Android mobile

3
713 reviews
6337 downloads

News and reviews about Google Chrome

13 May 2025

Gemini Enhances Google's Anti-Scam Measures Across Platforms

Gemini's AI algorithms enhance Google's detection of online scams on Chrome, Search, and Android, significantly reducing fraudulent activity.

Read more

11 Mar 2025

Installing Google Chrome on Windows 11: A Quick Guide

Learn how to download, install, and set Google Chrome as the default browser on Windows 11 with these simple steps.

Read more

05 Mar 2025

Google Enhances Password Manager with New Bulk Deletion Feature

Google is reportedly updating Password Manager to include a delete all option, simplifying the removal of saved credentials.

Read more

03 Mar 2025

Google Enhances Chrome with Android Malware Protection

Google introduces a new malware detector in Chrome for APK files, providing additional security for Android apps not from the Play Store.

Read more

04 Aug 2024

Google Releases Critical Chrome Security Update Addressing Key Vulnerability

Google has released a critical security update for Chrome, version 127.0.6533.88/89, addressing CVE-2024-6990, a memory vulnerability in the browser’s web graphics rendering engine. The update also includes two high-severity fixes. Users are advised to update and restart Chrome.

Read more

01 Aug 2024

Google Chrome Enhances Security with App-Bound Encryption in Version 127

Google Chrome version 127 for Windows now features app-bound encryption to enhance cookie protection and defend against malware. This update ties encrypted data to the app's identity, preventing unauthorized access. The new mechanism also safeguards passwords, payment data, and authentication tokens.

Read more

29 Jul 2024

Chrome Password Manager Bug Affects 15 Million Users, Issue Resolved

A bug in Chrome's password manager led to the loss of over 15 million passwords on July 24-25, affecting a quarter of users. The issue was specific to Chrome M127 on Windows. Google provided a temporary fix and has since resolved the glitch. Email verification issues for new Workspace accounts were also reported.

Read more

28 Jun 2024

Fake Update Malware Uses Social Engineering to Spread Harmful Software

A new fake update malware is spreading through social engineering tactics, posing as errors in Google Chrome, Word, and OneDrive. This harmful software tricks users into pasting a PowerShell "fix" into their systems, leading to malicious code downloads.

Read more

25 Jun 2024

Google Chrome Tests Audio Offload to Enhance Battery Life and Efficiency

Google Chrome is testing an audio offload feature on Windows 11 and 10 to improve battery life by shifting audio processing from the CPU to dedicated hardware. This experimental feature aims to reduce resource usage on battery-powered devices like laptops and tablets.

Read more

25 Jun 2024

Windows 11 on Arm: Mixed App Compatibility, Native Arm Versions Emerging

A recent review of Windows 11 on Arm highlights app compatibility. The author installed various apps, finding that 8 had native Arm versions, 7 ran well in emulation, and 1 did not work. This showcases the evolving landscape of software support for Arm-based Windows systems.

Read more