Ross ROSS = Recommend OSS · open-source software intelligence for agents

xaitax/Chrome-App-Bound-Encryption-Decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-mode, no admin required. observed · 2026-08-28

github.com/xaitax/Chrome-App-Bound-Encryption-Decryption · homepage · C · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

63/100

  • Activity 66
  • Release rhythm 69
  • Longevity 48
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 7.5
  • age_days: 675
  • days_rel: 209
  • days_push: 205
  • n_releases_24m: 21

Full methodology

Adoption not part of the score

1762 stars · 297 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollowing to decrypt browser data in memory. It extracts cookies, passwords, payment methods, and tokens from Chrome, Edge, Brave, and Avast without admin rights or disk writes.

Use cases

  • decrypt chrome app-bound encryption cookies
  • extract saved passwords from chromium browsers
  • bypass app-bound encryption on windows
  • red team tool for browser credential extraction
  • demonstrate process hollowing with direct syscalls
  • retrieve payment card data from chrome profiles
  • fileless in-memory browser data decryption
  • security research on chromium ABE COM server

When to choose

  • you are an authorized red teamer or pentester demonstrating browser credential theft on Windows
  • you research Chromium's App-Bound Encryption internals and COM-based security model
  • you need a fileless, user-mode proof of concept that evades user-land API hooks

When to avoid

  • you want to recover your own lost browser passwords through legitimate means
  • you need a cross-platform or defensive/analysis tool rather than an offensive exploit
  • your environment or jurisdiction prohibits use of credential-extraction tooling

Facets

cli-tool · maturity active

security penetration-testing reverse-engineering cryptography cli security penetration-testing reverse-engineering windows privacy windows cli app-bound-encryption chromium process-hollowing direct-syscalls reflective-dll-injection credential-extraction post-exploitation edr-evasion fileless-malware red-team

2 sources

Member repositories

RepositoryRoleHealth v2
xaitax/Chrome-App-Bound-Encryption-Decryptionmain63

For agents

markdown · JSON · MCP: product_card(name="xaitax/Chrome-App-Bound-Encryption-Decryption")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem