Chrome Android Auto Browse Privacy and Safety

On this page

Quick answer

Chrome auto browse can act with meaningful authority: it can use your signed-in browsing state, choose websites needed for a task, and share personal information with those sites. Google documents confirmations, takeover, permission prompts, prohibited-task recognition, and site or action restrictions, but explicitly says these safeguards do not protect against every risk.

The safe question is not only “Can auto browse do this?” It is “Which data, sites, actions, destinations, spend, and consequences am I authorizing—and how will I verify the result?”

The data and authority boundary

BoundaryWhat Google’s help page saysPractical control
Local browsing stateAuto browse can access the same sites you can, including signed-in sitesUse a bounded account and close unrelated sensitive sessions
Site selectionThe agent can choose sites to fulfill a requestName allowed or prohibited domains where the task permits
Personal informationIt may use data from Connected Apps and share information with a siteMinimize fields and verify destination before submission
Password ManagerIt can help sign in with permission; passwords are not shared with GeminiTreat sign-in as authority to the account, not a harmless convenience
Website actionsIt can click, fill, submit, schedule, communicate, or prepare transactionsRequire confirmation and verify the resulting site state

Connected Apps settings govern only part of the surface. Google says auto browse can work across websites even when the related app is not connected to Gemini Apps.

Prompt injection risk

Prompt injection is malicious or misleading content on a website, email, document, or other media that tries to redirect an AI agent. Google gives examples such as instructions that attempt to publish private data, send email to an external service, or expose insights from connected data.

Site and action restrictions help, but a page can still influence what the agent sees and does. For sensitive tasks:

  • avoid granting broad data context “just in case”;
  • separate research from execution;
  • specify allowed sites and a no-submission boundary;
  • inspect any proposed recipient, form, date, quantity, and price;
  • stop when the site or task scope changes unexpectedly.

Confirmation and takeover boundaries

Google says auto browse aims to ask for confirmation before certain actions, including sending communications, changing data, submitting forms, scheduling events, and accessing highly sensitive financial or health sites. It may request personal takeover for final financial transactions, accepting terms, or creating accounts.

“Aims to ask” is not an independent guarantee that every consequential variant will be classified correctly. A confirmation is useful only when it states the exact action, destination, data, amount, and effect the reviewer intends to approve.

You can stop the task or take it over at any time. If you give the task back, restate the remaining scope; do not assume the agent preserved an approval after a site, value, or destination changed.

Monitor and verify

Monitor closely when a task uses sensitive accounts, Connected Apps, personal data, money, legal or health information, or external communications. After the run:

  1. check the actual website or account state;
  2. confirm the right item, recipient, date, quantity, and amount;
  3. look for duplicate, pending, or partial actions;
  4. save the authorized scope and final evidence;
  5. revoke unnecessary site, Password Manager, or Connected Apps access.

The agent can mistakenly say a task is done, choose a wrong button, use the wrong quantity, or act without matching the user’s intent. Completion text is not completion evidence.

Read the access and limit requirements before enabling the feature, then use the readiness check for one bounded task.

Frequently asked questions

Can Chrome auto browse use sites where I am signed in?

Yes. Google says auto browse has access to the same local browsing state as the user, including sites where the user is signed in.

Can auto browse share personal information with a website?

Yes. Google says the feature may use personal information, including data from Connected Apps, and may share that information with a website while completing the requested task.

Do confirmations eliminate auto browse risk?

No. Google describes confirmations, takeover, permissions, prohibited-task recognition, and site or action restrictions as safeguards that reduce but do not eliminate risk. Monitoring and result verification remain necessary.

Official sources

Source check: August 19, 2026. Recheck data controls, Connected Apps, Password Manager, confirmation, takeover, prohibited-task, site restriction, retention, and privacy terms before authorizing a sensitive workflow.