We broke Chrome’s AppBound cookie encryption used in enterprise environments. Using timing-based attacks against the WebView lifecycle, we were able to recover encryption keys and decrypt secure cookies — no root or sandbox escape required. This affects managed Android profiles using MDM and AppBound mode.
Click to Open Code Editor