CDP Injection Exposes Active Chrome and Edge Sessions After Compromise

SpecterOps has detailed a post-exploitation technique that activates the Chrome DevTools Protocol inside running Chrome or Microsoft Edge processes on Windows. Attackers with prior code execution can access cookies, saved credentials, browsing data, and authenticated sessions, potentially bypassing protections designed to prevent off-device credential replay. The method does not exploit a browser vulnerability and relies on version-specific signatures, with public tooling tested only against selected Chrome and Edge releases. Defenders should monitor for process injection targeting chrome.exe or msedge.exe, including suspicious Sysmon Event IDs 8 and 10.

Reference: thehackernews.com