Offline decryption of Chrome-stored Login Data, Cookies and Web Data (credit cards, CVC, IBANs), covering both legacy DPAPI encryption (v10) and Chrome's App-Bound Encryption (ABE / v20).
Everything runs offline against copied artifacts (Local State, Login Data, Cookies, Web Data, DPAPI masterkeys, SYSTEM DPAPI/KSP material) — no interaction with a live Chrome process is required.
Warning
For educational and research purposes only. Use only on systems you own or have explicit permission to examine. Provided as-is, with no warranties of any kind.
This tool is the practical companion to my technical deep dive into Chrome's offline decryption chain (DPAPI v10 and App-Bound Encryption v20): From the Login Screen to Full Compromise → §4 Offline Chrome Credentials Decryption.
- v10 (DPAPI) decryption — unwraps the AES key from
Local Stateusing the user's DPAPI masterkey. - ABE / v20 (App-Bound) decryption — full offline chain: SYSTEM DPAPI userkey → SYSTEM masterkey → KSP key blob →
blob1→blob2→ key derivation from content flag (1, 2 or 3). - Login Data: site / login / decrypted password.
- Cookies: host / name / decrypted value.
- Web Data: credit cards, stored CVC, IBANs.
--infomode: read-only overview of what encryption version protects each entry, without decrypting anything.- Interactive prompts with caching: file paths, SID, etc. are cached per
Local Statefile in.data.jsonso repeated runs don't ask again. - Prints the derived
browser_key_v10/browser_key_v20in hex at the end of a--decryptrun.
- Python 3.10+
- Dependencies from
requirements.txt:
pip install -r requirements.txtpython3 chrome_abe_offline_decrypt.py --info -s "Local State" -l "Login Data" -c "Cookies" -w "Web Data"python3 chrome_abe_offline_decrypt.py --decrypt -s "Local State" -l "Login Data" -c "Cookies" -w "Web Data"You'll be prompted interactively for whatever the encryption chain requires:
- v10: masterkey file, account SID, password.
- ABE / v20 (only if App-Bound keys are present in
Local State): SYSTEM DPAPI userkey, SYSTEM DPAPI key file, KSP key file, then the account SID/masterkey/password again forblob2.
| Flag | Description |
|---|---|
-s, --localstate |
Path to Chrome's Local State JSON file |
-l, --logindata |
Path to Chrome's Login Data SQLite database |
-c, --cookies |
Path to Chrome's Cookies SQLite database |
-w, --webdata |
Path to Chrome's Web Data SQLite database |
--info |
Show encryption metadata only, no decryption |
--decrypt |
Decrypt the requested databases |
-v, --verbose |
Verbose logging (key sizes, decryption steps), optional for both --info and --decrypt |