Chrome Android Auto Browse Privacy and Safety
On this page
Quick answer
Chrome auto browse can act with meaningful authority: it can use your signed-in browsing state, choose websites needed for a task, and share personal information with those sites. Google documents confirmations, takeover, permission prompts, prohibited-task recognition, and site or action restrictions, but explicitly says these safeguards do not protect against every risk.
The safe question is not only “Can auto browse do this?” It is “Which data, sites, actions, destinations, spend, and consequences am I authorizing—and how will I verify the result?”
The data and authority boundary
| Boundary | What Google’s help page says | Practical control |
|---|---|---|
| Local browsing state | Auto browse can access the same sites you can, including signed-in sites | Use a bounded account and close unrelated sensitive sessions |
| Site selection | The agent can choose sites to fulfill a request | Name allowed or prohibited domains where the task permits |
| Personal information | It may use data from Connected Apps and share information with a site | Minimize fields and verify destination before submission |
| Password Manager | It can help sign in with permission; passwords are not shared with Gemini | Treat sign-in as authority to the account, not a harmless convenience |
| Website actions | It can click, fill, submit, schedule, communicate, or prepare transactions | Require confirmation and verify the resulting site state |
Connected Apps settings govern only part of the surface. Google says auto browse can work across websites even when the related app is not connected to Gemini Apps.
Prompt injection risk
Prompt injection is malicious or misleading content on a website, email, document, or other media that tries to redirect an AI agent. Google gives examples such as instructions that attempt to publish private data, send email to an external service, or expose insights from connected data.
Site and action restrictions help, but a page can still influence what the agent sees and does. For sensitive tasks:
- avoid granting broad data context “just in case”;
- separate research from execution;
- specify allowed sites and a no-submission boundary;
- inspect any proposed recipient, form, date, quantity, and price;
- stop when the site or task scope changes unexpectedly.
Confirmation and takeover boundaries
Google says auto browse aims to ask for confirmation before certain actions, including sending communications, changing data, submitting forms, scheduling events, and accessing highly sensitive financial or health sites. It may request personal takeover for final financial transactions, accepting terms, or creating accounts.
“Aims to ask” is not an independent guarantee that every consequential variant will be classified correctly. A confirmation is useful only when it states the exact action, destination, data, amount, and effect the reviewer intends to approve.
You can stop the task or take it over at any time. If you give the task back, restate the remaining scope; do not assume the agent preserved an approval after a site, value, or destination changed.
Monitor and verify
Monitor closely when a task uses sensitive accounts, Connected Apps, personal data, money, legal or health information, or external communications. After the run:
- check the actual website or account state;
- confirm the right item, recipient, date, quantity, and amount;
- look for duplicate, pending, or partial actions;
- save the authorized scope and final evidence;
- revoke unnecessary site, Password Manager, or Connected Apps access.
The agent can mistakenly say a task is done, choose a wrong button, use the wrong quantity, or act without matching the user’s intent. Completion text is not completion evidence.
Read the access and limit requirements before enabling the feature, then use the readiness check for one bounded task.
Frequently asked questions
Can Chrome auto browse use sites where I am signed in?
Yes. Google says auto browse has access to the same local browsing state as the user, including sites where the user is signed in.
Can auto browse share personal information with a website?
Yes. Google says the feature may use personal information, including data from Connected Apps, and may share that information with a website while completing the requested task.
Do confirmations eliminate auto browse risk?
No. Google describes confirmations, takeover, permissions, prohibited-task recognition, and site or action restrictions as safeguards that reduce but do not eliminate risk. Monitoring and result verification remain necessary.
Official sources
- Chrome Help: Complete tasks with auto browse
- Google Security Blog: Architecting security for agentic browsing
Source check: August 19, 2026. Recheck data controls, Connected Apps, Password Manager, confirmation, takeover, prohibited-task, site restriction, retention, and privacy terms before authorizing a sensitive workflow.