It comes down to a tradeoff between usability, maintainability and security. Yes you can get the cookie and reuse it on another device. But that doesn't in itself mean it's all super unsafe.
- The cookie should have flags like HttpOnly, SameSite and Secure, so it's not just out there to be grabbed by whatever malicious script on a random website. A hacker would need physical access to the device or have a phishing mechanism in place and trick the user into logging in via their phishing url.
- Sessions have a timeout, so you can't just copy or steal the cookie and use it indefinitely
You could consider all kinds of countermeasures, but they may not be worth the effort or come with their own downsides. For example:
- remove anonymous access. But then you'd need to build your own html+javascript login and onboarding pages, including your mfa and forgot password mechanisms. That may not be what you want in a low code environment. Also if your application needs anonymous access apart from the login page, you might as well build your login page in Mendix. Building your own login page may even end up being less secure.
- ip-based validation, maybe like the module by GurumoorthyJ does. But that may break session authentication for published rest services. Also users would need to login again when they switch wifi or VPN networks.
- users can have only one session at a time by default, so even if the cookie was stolen before it timed out and the session is kept alive, a fresh login would kill it. And if you do allow concurrent sessions (to accomodate session authentication in rest services for instance), you could add a check in the home page microflow and kill existing sessions from another ip there.
- a quick win may be to let users reauthenticate for some really sensitive actions, like changing their password or executing something irreversible.
Also, this is why users should be vigilant against phishing and lock their screens when they move away from their device etc.