Norton 360 appears to conflict with Microsoft Edge's Device Bound Session Credentials (DBSC), causing repeated Google sign-out

Issue Abstract: Google log-in not persistent; tied to Device Bound Session Credentials

Detailed Description: My Google account sign-in on this desktop was not persisting. After signing in, the session would silently drop after roughly 1-5 hours, requiring a full sign-in (including 2-Step Verification) again. This happened consistently regardless of:

- Edge cookie settings (third-party cookies allowed for google-dot-com, “clear on close” disabled, Tracking Prevention set to Balanced)

- Browser extensions (reproduced with all extensions, including Norton’s, fully disabled)

- Sleep/lock state (reproduced with sleep and screen lock both disabled, computer fully awake the entire time)

- Public IP address (unchanged throughout, confirmed via other devices on the same network staying signed in fine)

- Windows Task Scheduler and Edge enterprise policies (none found)

The Google session cookies themselves (SID, HSID, SSID, APISID, SAPISID, and the __Secure- variants) remained present and valid (expiration roughly a year out) even at the moment of sign-out, ruling out cookie deletion.

The issue only affects this one desktop; two other laptops and two phones signed into the same Google account, on the same home network, have had no sign-in issues.

Root Cause Found: Microsoft Edge 147 (stable, released April 2026) introduced Device Bound Session Credentials (DBSC), which ties a session to a device-bound cryptographic key and requires periodic proof-of-possession to refresh the session, separate from the standard cookie expiration. When I disabled DBSC via edge://flags (search “device bound” and set to Disabled), then fully restarted Edge and signed out off/back into Google, the session remained persistent for 5+ hours of testing (checked at hour 1, 2, and 5), well past where it was previously failing. It has now been 36 hours and the login still persists.

This points to Norton’s real-time/process-level protection interfering with the DBSC key refresh handshake, perhaps caused by a recent Norton, Windows, or Edge update.

Request: Has anyone else seen this? Is there a known compatibility fix planned, or an exclusion I can set in Norton for Edge’s DBSC-related processes so I can re-enable this security feature without losing session persistence?

Happy to provide further diagnostic details if helpful.

Product & version number: Norton 360, Version 26.7.11086 (build 26.7.11086.990)

OS details: Microsoft Windows 11 Home, Version 10.0.26200 Build 26200

Microsoft Edge: Version 151.0.4129.107 (Official build) (64-bit)

What is the error message you are seeing? There is no error message.

If you have any supporting screenshots, please add them: Not applicable.

@Jack_Leonard I just updated Edge to the latest version 151.0.4129.107 (Official build) (64-bit). Checking this out my side to compare with your posting.

SA