Overview
- Device Bound Session Credentials entered open beta for Chrome on Windows, binding session cookies to individual devices to prevent hijacking attempts.
- Passkey support is now generally available to more than 11 million Google Workspace users, and admins can audit enrollments or restrict them to physical security keys.
- A closed beta of the Shared Signals Framework will let select partners exchange critical security events via the OpenID standard in near real time.
- Project Zero’s Reporting Transparency trial will publicly share upstream vulnerability reports within a week of vendor disclosure, starting with issues in Windows, Dolby Unified Decoder and Google BigWave.
- Google launched these measures in response to a 37 percent share of account takeovers driven by credential theft and an 84 percent rise in infostealer attacks in 2024.