- Sources: BleepingComputer, Reddit discussion
- Summary: Jamf Threat Labs reports that the malware duplicates the victim's Chromium profile into a hidden headless browser on the infected host and drives it over the Chrome DevTools Protocol, so the attacker operates authenticated sessions while the browser, host, and network identifiers stay those of the victim. Jamf states profile duplication works across seven Chromium browsers including Chrome, Edge, Brave, Arc, Opera, Vivaldi, and Chromium, because they share the same DevTools Protocol, launch flags, and cookie encryption, and that on macOS 26, when the malware cannot recover the existing Chrome Safe Storage key, a fallback replaces it with an attacker-supplied value, leaving previously stored cookies and passwords permanently unreadable to the victim while the attacker can still decrypt them. Delivery is a ClickFix lure on a fake GitHub download page that asks the user to paste a terminal command, and the payload captures the macOS login password to reach keychain data. No software vulnerability or affected version range is involved, because delivery depends on the user pasting the command, and macOS 26 is named only as the condition for the Safe Storage fallback.
- Why it matters: Session-theft detection that keys on a new device, a new IP, or impossible travel does not fire on a session driven from the victim's own host.
- Follow-up: Jamf dates the research 2026-08-13 and BleepingComputer reports it 2026-08-16, so watch for the vendor post itself and for confirmation of the macOS 26 Safe Storage fallback.
send feedback on this story