56
Fighting cookie theft using device bound sessions
(blog.chromium.org)
This is a most excellent place for technology news and articles.
I don't think WebAuthn protects against cookie theft. WebAuthn better protects the login process. But if the result of the login process is still a session/auth cookie, that can be stolen like any other cookie.