Cybersecurity & Privacy — 2026-03-23
VoidStealer Introduces Novel Debugger Technique to Bypass Chrome's Application-Bound Encryption
VoidStealer v2.0 is the first infostealer using hardware breakpoints to extract Chrome's v20_master_key directly from browser memory, bypassing Application-Bound Encryption without requiring privilege escalation or code injection. The malware launches a hidden browser process, attaches as a debugger, sets hardware breakpoints on a target DLL, then reads the register holding the plaintext master key. Because hardware breakpoints use CPU registers rather than code modification, the technique evades detection by leaving memory untouched. VoidStealer has operated as MaaS since late 2025, with v2.1 deployed March 18.