xaitax/Chrome-App-Bound-Encryption-Decryption
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-mode, no admin required. observed · 2026-08-28
Health v2 · maintenance only
63/100
- Activity 66
- Release rhythm 69
- Longevity 48
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 7.5
- age_days: 675
- days_rel: 209
- days_push: 205
- n_releases_24m: 21
Adoption not part of the score
1762 stars · 297 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollowing to decrypt browser data in memory. It extracts cookies, passwords, payment methods, and tokens from Chrome, Edge, Brave, and Avast without admin rights or disk writes.
Use cases
- decrypt chrome app-bound encryption cookies
- extract saved passwords from chromium browsers
- bypass app-bound encryption on windows
- red team tool for browser credential extraction
- demonstrate process hollowing with direct syscalls
- retrieve payment card data from chrome profiles
- fileless in-memory browser data decryption
- security research on chromium ABE COM server
When to choose
- you are an authorized red teamer or pentester demonstrating browser credential theft on Windows
- you research Chromium's App-Bound Encryption internals and COM-based security model
- you need a fileless, user-mode proof of concept that evades user-land API hooks
When to avoid
- you want to recover your own lost browser passwords through legitimate means
- you need a cross-platform or defensive/analysis tool rather than an offensive exploit
- your environment or jurisdiction prohibits use of credential-extraction tooling
Facets
cli-tool · maturity active
security penetration-testing reverse-engineering cryptography cli security penetration-testing reverse-engineering windows privacy windows cli app-bound-encryption chromium process-hollowing direct-syscalls reflective-dll-injection credential-extraction post-exploitation edr-evasion fileless-malware red-team
2 sources
- readme: https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption · fetched 2026-08-28 · 0a4bfaa8e63b
- homepage: https://primepage.de · fetched 2026-08-29 · 33a8b8d707dc
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| xaitax/Chrome-App-Bound-Encryption-Decryption | main | 63 |
For agents
markdown · JSON · MCP: product_card(name="xaitax/Chrome-App-Bound-Encryption-Decryption")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem