Session hijacking happens after you sign in. Whoever steals your session cookie gets into your account without a password and without a second factor, and antivirus does not fix it because the stolen cookie keeps working. Chrome now ties sessions to the device with DBSC, while Firefox still stores its cookie database unencrypted. How the theft works and what really helps.