Google says it's seen a rise in shady and spam websites using 'Back button hijacking' to try and trap or manipulate users ...
Stolen session cookies bypass MFA because tokens remain valid for hours or days, enabling silent account takeovers without triggering security alerts.