Nothing in Google's authentication was bypassed. The malware took the session and replayed it
2026-09-08Security
JSCeal steals cookies from Chromium browser profiles and reconstructs the session to reach a victim's Google account. That is being written up as bypassing Google authentication. It is not — no authentication mechanism is defeated, and the difference decides whether you go looking for an auth fix that does not exist.