VoidStealer grabs Chrome’s master key using a clever debugging exploit.
Mar 22, 2026 // 19:57 - Norina Velotta


A data-stealing malware named VoidStealer is using a new technique to get around Chrome’s Application-Bound Encryption (ABE) and steal the master key needed to decrypt private information stored in the browser.

This new method is more covert, using hardware breakpoints to grab the v20_master_key, which is used for both encrypting and decrypting data, directly from the browser’s memory, without needing special permissions or injecting code.

A report from Gen Digital, the company that owns Norton, Avast, AVG, and Avira, says that this is the first time an infostealer has been seen using this kind of method in the real world.

Google added ABE to Chrome 127 in June 2024, as a new way to protect cookies and other sensitive data. It makes sure that the master key stays encrypted on the hard drive and cannot be accessed normally by users.

To decrypt the key, you need the Google Chrome Elevation Service, which runs with high-level system privileges, to confirm the process asking for it.

However, this system has been circumvented by several data-stealing malware families and has even been shown in open-source tools. Although Google has released updates to block these bypasses, more recent malware versions have reportedly continued to succeed using different methods.

“VoidStealer is the first data stealer observed in action that uses a new technique to bypass Application-Bound Encryption (ABE). This technique uses hardware breakpoints to extract the v20_master_key directly from the browser’s memory,” says Vojtěch Krejsa, a threat researcher at Gen Digital.

VoidStealer is a malware-as-a-service (MaaS) platform that has been advertised on dark web forums since at least mid-December 2025. The malware introduced the new ABE bypass method in version 2.0.

VoidStealer’s method for extracting the master key focuses on the short period when Chrome’s v20_master_key is briefly unencrypted in memory during decryption.

Specifically, VoidStealer starts a browser process that is hidden and paused, attaches itself to it as a debugger, and waits for the target browser DLL (chrome.dll or msedge.dll) to load.

Once loaded, it scans the DLL for a specific string and the LEA instruction that refers to it, using that instruction’s memory address as the target for the hardware breakpoint.

Next, it sets a breakpoint across existing and new browser threads, waits for it to trigger during startup while the browser decrypts protected data, then reads the register holding a pointer to the unencrypted v20_master_key and extracts it using the ‘ReadProcessMemory’ function.

Gen Digital explains that the best time for the malware to do this is during browser startup, when the application loads ABE-protected cookies early, forcing the master key to be decrypted.

The researchers believe that VoidStealer likely did not invent this technique but instead took it from the open-source project ‘ElevationKatz,’ part of the ChromeKatz cookie-dumping toolset used to demonstrate vulnerabilities in Chrome.

While there are some code differences, the implementation appears to be based on ElevationKatz, which has been available for over a year.

BleepingComputer contacted Google for a statement about this bypass method being used by threat actors, but no response was received by the time of publication.

#chrome’s  #clever  #debugging  #exploit  #grabs  #key  #master  #news  #using  #voidstealer   —   News