Your Chrome Passwords May Not Be as Safe as You Think
If you use Google Chrome and trust it to save your passwords, banking credentials, or UPI app logins — there's a new threat you need to know about. A malware called VoidStealer has cracked open one of Chrome's most advanced security systems using a technique that nobody had seen in the wild before. And the scary part? It doesn't need admin access, doesn't need to inject code into your system, and leaves almost no trace. Security researchers at Gen Digital (the company behind Norton, Avast, and Avira) flagged this as a first-of-its-kind attack in March 2026.
This isn't theoretical research. VoidStealer is an active malware-as-a-service (MaaS) platform — which means cybercriminals can literally rent it on the dark web to attack people like you and me. Let's break down exactly what it does, how it works, and most importantly, how to protect yourself.
What Is Chrome's Application-Bound Encryption (ABE)?
To understand why this attack is significant, you need to know what it bypassed. In July 2024, Google released Chrome 127 with a security feature called Application-Bound Encryption (ABE). The idea was simple but powerful: encrypt all your saved passwords, cookies, and session tokens with a secret key — and lock that key behind a Windows SYSTEM-level service called the Google Chrome Elevation Service.
Premium Content
You've read all your free articles today. Subscribe to continue reading.
You've used 3 of 3 free articles today.
Subscribe NowAlready subscribed? Sign in




Comments (0)
Be the first to comment!