Resource icon

What is a session cookie, and why can theft bypass MFA?

A session cookie is data a website gives your browser after sign-in so you do not need to enter your password on every page. It is not the same as your password. Some stolen active session cookies can be reused to act as the signed-in user without repeating the normal MFA check.

Quick example​

You sign in to webmail with a password and authenticator. Malware on the computer steals an active browser session. An attacker may be able to open the account while that session is still valid, even though they do not know the authenticator code.

What to do​

If you suspect device compromise, clean the device first, then use the service's security controls to sign out other sessions and change the password. Check account activity and recovery settings. Changing a password does not revoke every session on every service automatically. MITRE ATT&CK's session-cookie entry explains this distinction.

Practical distinction​

If an account has a 'sign out all devices' control, use it after securing the device. Do not assume a password reset ended every browser session; verify the provider's actual session behavior.
Posted by
Jack
Views
6
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack