Chrome Cookie解密遇CryptUnprotectData参数错误,求排查方案
解决Chrome密钥解密时的CryptUnprotectData参数错误问题
你遇到的pywintypes.error: (87, 'CryptUnprotectData', 'The parameter is incorrect.')错误,根源在于从Local State中解码出的加密密钥带有**"DPAPI"前缀(前5个字节)**,直接传入CryptUnprotectData会导致参数不合法。
修正后的密钥获取代码
import os import json import base64 import win32crypt # 定位Chrome的Local State文件 local_state_path = os.path.expandvars(r"%LOCALAPPDATA%\Google\Chrome\User Data\Local State") with open(local_state_path, "r", encoding="utf-8") as local_state_file: local_state = json.load(local_state_file) # 解码加密密钥并移除DPAPI前缀 encrypted_key = base64.b64decode(local_state["os_crypt"]["encrypted_key"]) # 剔除前5个字节的"DPAPI"标识字符串 encrypted_key = encrypted_key[5:] # 调用系统API解密得到实际密钥 key = win32crypt.CryptUnprotectData(encrypted_key, None, None, None, 0)[1]
额外注意事项
- 确保你的Python程序有读取Local State文件的权限,不要跨用户读取Chrome数据(比如管理员进程读取普通用户的Chrome文件会有权限问题)
- 后续解密Cookie时,Chrome 80+版本的加密Cookie值会带有
v10前缀,需要先剔除前缀,再用AES-GCM模式结合上面获取的密钥进行解密 - 若你处理的是Edge、Chromium等其他基于Chromium的浏览器,只需调整Local State和Cookies文件的路径,密钥处理逻辑完全一致
内容的提问来源于stack exchange,提问作者David
相关产品推荐
相关产品推荐

