Your Credentials Are Still Mine: Extracting Credentials from Latest Browsers

No ratings

Presented at DEF CON Singapore 2026 by

Modern browsers are finally getting serious about local credential protection. Chrome introduced App-Bound Encryption (ABE) to bind cookies and passwords to application identity, while Firefox 144+ replaced legacy 3DES with AES-256-CBC for stored credentials. These protections are designed to make post-compromise credential extraction significantly harder. But harder does not mean gone. In this talk, we deconstruct the security assumptions behind Chromium's App-Bound Encryption and Firefox's updated credential protection model, and show why practical extraction paths still remain viable with only standard user privileges. Without kernel exploits, browser vulnerabilities, or admin rights, we demonstrate fully automated recovery of passwords and cookies from Chrome, Edge, and Firefox 144+ under default configurations. Rather than treating stronger local encryption as the end of the story, this talk explores the gap between improved decryption controls and real-world post-compromise security. Through practical extraction workflows, we show where these protections help, where they still fall short, and why browser credential theft remains a persistent problem on compromised endpoints.