
HackBrowserData
HackBrowserData is a command-line tool for decrypting and exporting browser data (passwords, history, cookies, bookmarks, credit cards, download history, localStorage, sessionStorage and extensions) from the browser. It supports the most popular Chromium-based browsers and Firefox on Windows, macOS and Linux, plus Safari on macOS.
It can also decrypt data across machines and operating systems: export the master keys on the origin host, then decrypt a copy of the data offline on any other host — even for a browser that the analyst host's OS cannot run (see Cross-host decryption).
Disclaimer: This tool is only intended for security research. Users are responsible for all legal and related liabilities resulting from the use of this tool. The original author does not assume any legal responsibility.
Supported Data Categories
| Category | Chromium-based | Firefox | Safari |
|---|---|---|---|
| Password | ✅ | ✅ | ✅ |
| Cookie | ✅ | ✅ | ✅ |
| Bookmark | ✅ | ✅ | ✅ |
| History | ✅ | ✅ | ✅ |
| Download | ✅ | ✅ | ✅ |
| Credit Card | ✅ | - | - |
| Extension | ✅ | ✅ | ✅ |
| LocalStorage | ✅ | ✅ | ✅ |
| SessionStorage | ✅ | - | - |
Supported Browsers
On macOS, some Chromium-based browsers require a current user password to decrypt.
Password decryption may fail on macOS 26.4 or later.
| Browser | Windows | macOS | Linux |
|---|---|---|---|
| Chrome | ✅² | ✅ | ✅ |
| Chrome Beta | ✅² | ✅ | ✅ |
| Chromium | ✅ | ✅ | ✅ |
| Edge | ✅² | ✅ | ✅ |
| Brave | ✅² | ✅ | ✅ |
| Opera | ✅ | ✅ | ✅ |
| OperaGX | ✅ | ✅ | - |
| Vivaldi | ✅ | ✅ | ✅ |
| Yandex | ✅ | ✅ | - |
| CocCoc | ✅² | ✅ | - |
| Arc | ✅ | ✅ | - |
| DuckDuckGo³ | ✅ | - | - |
| QQ³ | ✅ | - | - |
| 360 ChromeX³ | ✅ | - | - |
| 360 Chrome³ | ✅ | - | - |
| DC Browser³ | ✅ | - | - |
| Sogou Explorer³ | ✅ | - | - |
| Firefox | ✅ | ✅ | ✅ |
| Safari¹ | - | ✅ | - |
¹ Safari requires Full Disk Access; enable it in System Settings → Privacy & Security → Full Disk Access if extraction returns empty results.
² On Windows, decrypting Chromium 127+ cookies (Chrome / Chrome Beta / Edge / Brave / CocCoc) requires the App-Bound Encryption payload built via
make build-windows— see Building from source below.³ These browsers ship only on Windows, but their data is decryptable on any OS: pull the files with
archive, export the keys withdumpkeys, then decrypt on macOS or Linux withrestore— see Cross-host decryption.
Getting Started
Install
Installation of HackBrowserData is dead-simple, just download the release for your system and run the binary.
In some situations, this security tool will be treated as a virus by Windows Defender or other antivirus software and can not be executed. The code is all open source, you can modify and compile by yourself.
Building from source
Requires Go 1.20+.
git clone https://github.com/moonD4rk/HackBrowserData
cd HackBrowserData
go build ./cmd/hack-browser-data/
Cross-platform build
# For Windows (standard build, no Chromium 127+ ABE cookie support)
GOOS=windows GOARCH=amd64 go build ./cmd/hack-browser-data/
# For Linux
GOOS=linux GOARCH=amd64 go build ./cmd/hack-browser-data/
Windows build with App-Bound Encryption (optional)
Chrome / Chrome Beta / Edge / Brave / CocCoc 127+ protect cookies with App-Bound Encryption. Decrypting those cookies requires a small C payload — Zig (0.13+) is the recommended C toolchain (the Makefile calls zig cc). MinGW-w64 gcc can also build the sources manually if you bypass make payload.
# 1. Install Zig
brew install zig # macOS
scoop install zig # Windows (scoop)
# or download from https://ziglang.org/download/
# 2. Build the payload (outputs crypto/windows/payload/abe_extractor_amd64.bin)
make payload
# 3. Build hack-browser-data.exe with the ABE payload embedded
make build-windows
The resulting hack-browser-data.exe includes full ABE cookie decryption on Chromium 127+.
Usage
$ hack-browser-data -h
hack-browser-data decrypts and exports browser data from Chromium-based
browsers and Firefox on Windows, macOS, and Linux.
GitHub: https://github.com/moonD4rk/HackBrowserData
Usage:
hack-browser-data [flags]
hack-browser-data [command]
Available Commands:
archive Pack decryption-relevant profile files into a zip for cross-host restore
dump Extract and decrypt browser data (default command)
dumpkeys Export Chromium master keys as JSON for cross-host decryption
help Help about any command
list List detected browsers and profiles
restore Decrypt copied profile data using exported master keys
version Print version information
Flags:
-b, --browser string target browser: all|chrome|firefox|edge|... (default "all")
-c, --category string data categories (comma-separated): all|password,cookie,... (default "all")
-d, --dir string output directory (default "results")
-f, --format string output format: csv|json|cookie-editor (default "json")
-h, --help help for hack-browser-data
--keychain-pw string macOS keychain password
-p, --profile-path string custom profile dir path, get with chrome://version
-v, --verbose enable debug logging
--zip compress output to zip
Use "hack-browser-data [command] --help" for more information about a command.
dump - Extract and decrypt browser data (default)
Running hack-browser-data without a subcommand defaults to dump.
| Flag | Short | Default | Description |
|---|---|---|---|
--browser |
-b |
all |
Target browser (all|chrome|firefox|edge|...) |
--category |
-c |
all |
Data categories, comma-separated (all|password|cookie|bookmark|history|download|creditcard|extension|localstorage|sessionstorage) |
--format |
-f |
json |
Output format (csv|json|cookie-editor) |
--dir |
-d |
results |
Output directory |
--profile-path |
-p |
Custom profile dir path, get with chrome://version | |
--keychain-pw |
macOS keychain password | ||
--zip |
false |
Compress output to zip |