Information
This setting turns on App-Bound Encryption to protect saved passwords and session cookies on Windows. Instead of letting any app running on the user's computer read Chrome's data, Chrome locks the encryption keys to its own application identity. This stops background malware from easily stealing login tokens, though it won't stop an advanced attacker who already has admin rights or hooks directly into Chrome. Because these keys are locked tightly to the physical computer, cookies won't sync between different workstations if your organization uses roaming user profiles.
Note: Setting the policy to Disabled has a detrimental effect on Google Chrome's security as unknown and potentially hostile apps can retrieve encryption keys used to secure data.
Information-stealing malware (infostealers) frequently targets browser profile directories to exfiltrate active session tokens and bypass Multi-Factor Authentication (MFA). Traditionally, Chrome utilized the Windows Data Protection API (DPAPI), which safely isolates data from separate OS user profiles but permits any unprivileged application running under the same user context to request token decryption.
Enforcing this policy ensures that primary decryption keys are strictly isolated via an elevated service gatekeeper that validates the canonical installation path of the calling application. This effectively prevents same-user, same-privilege malicious binaries from trivially executing automated DPAPI unwrapping commands against Chrome's local database files. Leaving this feature unconfigured or disabled exposes session tokens to rapid, frictionless software-level harvesting by malware.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable Application-Bound Encryption
Impact:
Actively binding encryption keys to the underlying hardware layer increases the work factor for attackers and forces noisy code injection or administrative elevation attempts. However, because keys are bound directly to the local hardware security state, this feature prevents the encrypted data from being portable. Organizations utilizing network-based roaming browser profiles may experience data synchronization or password access failures unless explicit corporate roaming profile configurations are handled.