Chrome DevTools Protocol Exploitation Enables Session Hijacking in Windows Browsers
Researchers have discovered a post-exploitation technique using Chrome DevTools Protocol (CDP) to hijack authenticated sessions in running Chrome or Edge processes on Windows, requiring prior code execution. The method bypasses certain security measures and can be detected via Sysmon Event IDs 8 and 10, though it's limited to specific browser versions.
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions.
The technique assumes that an operator already has code execution on the Windows host and does not involve
*** END OF TRANSMISSION ***