Exploiting DPAPI and Local State Decryption for Web Cookie Session Theft in Cross-Device Chrome Migrations
Kyle Herman, Lei Chen · 2025
Multifactor Authentication (MFA) has grown in popularity for application and operating system security. In response, cyber criminals have turned to web browser session theft to defeat MFA. With a valid session ID, cyber criminals can bypass username/password and MFA requirements and gain access to sensitive systems such as email. Once accessed, attackers can extract sensitive information from the victim's account and use it for targeted phishing or mass spam campaigns. Prior research has focused on Man-in-the-Middle (MitM) attacks or Cross-Site-Scripting (XSS) attacks from vulnerable servers. A more realistic explanation for the increase in session theft is malware and users who are tricked into installing it. Google Chrome uses Windows Data Protection API (DPAPI) to encrypt and store passwords, session cookies and authentication tokens. To simulate malware, this study utilized a PowerShell script to decrypt the Local State file to defeat DPAPI. The decryption key was then utilized to decrypt the cookies in the SQLite database and provide valid session IDs.