Hi there,
sessions are created with their own "id". What ever you store in a sessions "belongs" to 1 user.
Take a look in your /tmp folder where the sessions are createt, where you can learn what a sessions contains, and how it is named.
When a user leav your site, no one can take over that session, unless it is a hacker. But that is not a PHP problem, it's more a server security problem!
Good luck!