Skip to content

Return of the Cookie Monster - #2851

Open
carlospolop wants to merge 4 commits into
masterfrom
update_Return_of_the_Cookie_Monster_bd3373b0119173e3
Open

carlospolop wants to merge 4 commits into
masterfrom
update_Return_of_the_Cookie_Monster_bd3373b0119173e3

Conversation

@carlospolop

@carlospolop carlospolop commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Blog URL

https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft

Blog Title

Return of the Cookie Monster

Blog high summary

A post-compromise Windows technique injects into a live Chrome or Edge process and calls Chromium's internal StartRemoteDebuggingServer, enabling CDP on localhost:9222 without relaunching the browser. This preserves the user's authenticated profile despite Chrome 136+ launch-flag protections.

CDP Toolkit can enumerate tabs, dump cookies, inspect history, bookmarks, extensions, passwords, capture screenshots, and browse through the user's session. Sysmon Event 8 plus Event 10 GrantedAccess=0x143a can indicate the injection.

PR changes

Errors

mdbook build unavailable

@carlospolop

carlospolop commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator Author

merge

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Sunday editorial verdict: defer
Reviewed head: 56e8ddb65c57174c7e86ab9982f072339b45a1ff

Documents post-compromise activation of Chrome DevTools Protocol inside a live Windows Chromium process, including the distinct process-isolation path, version-dependent symbol resolution, and failure constraints.

Adds source-backed coverage of authenticated-browser artifact collection and interaction, with Windows credential-theft navigation and contextual detection guidance.

  • The proposal materially expands the base page's brief CDP-Enabler coverage with reusable process-isolation, compatibility, signature-refresh, extraction, and interaction details.
  • Primary repositories and the original research support the added prerequisites, mechanisms, limitations, and tool behavior.
  • The existing CDP abuse page remains the nearest canonical destination; the Windows credential page adds a useful discovery link.
  • Markdown fences, citations, references, banners, and the relative reference target were checked. No editorial repair was necessary.
  • The base changed after review; source/coverage and candidate validation need a fresh review. No repairs or merge signal were published.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Sunday editorial verdict: defer
Reviewed head: 56e8ddb65c57174c7e86ab9982f072339b45a1ff

Documents post-compromise activation of CDP inside authenticated Chrome and Edge processes, including the Windows Process Isolation variant, version-specific signature constraints, and browser-assisted collection workflows. Adds Windows credential-theft navigation to the canonical CDP page.

  • The isolation-compatible activation path, signature-refresh constraints, and browser-assisted collection workflows are reusable, source-supported additions beyond the base page's general Edge injection coverage.
  • The existing CDP page remains the canonical destination; the Windows credential-theft cross-reference resolves to its live-process section.
  • Removed the PR-added generic detection subsection, restored the existing concise detection context, and renumbered the remaining references and citations.
  • The base changed after review; source/coverage and candidate validation need a fresh review. No repairs or merge signal were published.

Editorial repairs:

  • src/linux-hardening/software-information/electron-cef-chromium-debugger-abuse.md: Removed generic detection material, restored the existing detection paragraph, and repaired reference numbering while preserving the qualifying CDP activation and browser-assisted workflow additions.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Sunday editorial verdict: ready
Reviewed head: db198fc54f10685abd1f25f243c5424065300daf

Documents post-compromise CDP activation inside authenticated Chrome and Edge processes, including a Process Isolation-compatible path and version-specific signature maintenance. It also covers browser-assisted collection, saved-password autofill constraints, and live session interaction without offline App-Bound Encryption decryption.

  • The Process Isolation path, unique-signature failure behavior, signature-refresh workflow, WebUI collection, autofill constraints, and browser-takeover modes are source-supported, reusable additions beyond the existing Edge-only mechanism.
  • The existing CDP abuse page remains the canonical destination; the Windows credential-theft page adds a valid discovery link.
  • Removed the proposed generic Sysmon detection expansion because defensive material does not qualify for updater intake; preserved the existing brief detection paragraph.
  • Removed an unsupported allocator rationale and clarified the distinction between BOF modes and the repository helper script.
  • No relevant pending PR duplicates this mechanism or either affected path.

Editorial repairs:

  • src/linux-hardening/software-information/electron-cef-chromium-debugger-abuse.md: Removed the detection expansion and unsupported allocator rationale, clarified BOF/helper roles, and renumbered remaining references while preserving the source-backed offensive workflows.

@carlospolop

carlospolop commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator Author

merge

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Sunday editorial verdict: ready
Reviewed head: 4186ae6a804d346c8f3013c959b75e17ac239080

Documents post-compromise activation of CDP in live x64 Chrome and Edge processes, including Chrome Process Isolation handling, version-specific signature maintenance, and authenticated browser access without relaunching the profile.

Adds source-backed CDP Toolkit workflows for browser artifacts, autofill-backed credential access, and interactive session use, with a Windows credential-theft navigation link.

  • The current base already covers the original Edge injection mechanism, but not the submitted Chrome Process Isolation path, strict signature-resolution constraints, or detailed authenticated-browser workflows.
  • The CDP-Enable-BOF and CDP Toolkit repositories, the original CDP-Enabler research, and the SpecterOps article support the retained mechanisms, prerequisites, compatibility details, and limitations.
  • The existing debugger-abuse page is the canonical mechanism page; the Windows credentials page appropriately adds only a cross-reference.
  • Editorial repairs clarified the x64 limitation and replaced an inferred handle description with the source's precise query-limited-handle behavior.
  • PR How Browser Exploits Work DarkSword, CVE-2025-43529, and the... #2848 was inspected and changes an unrelated iOS WebKit exploitation page; no overlapping pending proposal was found.
  • References, citations, banners, code fences, and the new reference-block destination were checked successfully.

Editorial repairs:

  • src/linux-hardening/software-information/electron-cef-chromium-debugger-abuse.md: Clarified the BOF's x64 compatibility boundary and the query-limited handles used by its Chrome Process Isolation path.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

merge

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant