Can Gemini in Chrome use saved passwords? Auto Browse Risks

Can Gemini in Chrome Use Your Saved Passwords? Auto Browse Security Explained

Gemini in Chrome can now do more than summarize a webpage or answer questions about an open tab. With auto browse, it can work through multi-step web tasks for you, such as comparing products, filling out parts of a booking flow, scheduling appointments, and navigating websites while you watch.

That raises an obvious security question: Can Gemini in Chrome use your saved passwords?

The short answer is yes, but not in the way many people assume. Google says Gemini in Chrome can get help from Google Password Manager to sign in to approved sites after you give permission. However, Google also says Google Password Manager does not share the actual password with Gemini in Chrome, and the model does not have direct access to your stored passwords.

That distinction matters. Gemini may be able to use your signed-in browser session and trigger a Password Manager-assisted login, but that is different from the AI model being able to read a list of your passwords.

What is Gemini in Chrome auto browse?

Auto browse is Google’s agent-style browsing feature for Gemini in Chrome. Instead of only giving you information, Gemini can take a task, create a plan, visit websites, click buttons, fill in forms, and move through several steps on your behalf.

Google gives examples such as comparing products, looking for deals, adding items to a cart, finding travel accommodation, making restaurant reservations, and scheduling appointments. You can see the task happening in the browser and take control if Gemini needs help or if you want to stop it.

This is the same broader shift we discussed in our guide to AI browser security: once an AI can act inside a browser rather than only answer questions, permissions and session access become much more important.

Can Gemini actually see your saved passwords?

According to Google, no. Google says Password Manager does not share your passwords with Gemini in Chrome. When Gemini needs to sign in to a website, Chrome can use Google Password Manager to complete the login after you have granted permission for that site.

Google’s Chrome security team goes even further and says the model does not have direct access to stored passwords. Chrome is designed to keep the credential itself behind a browser-controlled boundary while still allowing the browser to perform a login when you approve it.

You can read Google’s current explanation in its Gemini in Chrome auto browse help page and its Chrome agentic security overview.

So what does “Gemini can use saved passwords” really mean?

Google sometimes describes the feature in simpler language by saying Gemini can use your logged-in accounts and saved passwords to handle web errands. The more precise explanation is that Chrome can use Password Manager on Gemini’s behalf while keeping the raw password hidden from the AI model.

A practical example makes this clearer:

  1. You ask Gemini in Chrome to find and start booking a hotel.
  2. The task requires signing in to a travel website.
  3. Gemini reaches the login page.
  4. Chrome asks for permission before using Google Password Manager.
  5. If you approve it, Password Manager can fill or submit the saved credentials.
  6. Gemini continues the task without being given the actual password text.

This is closer to letting an assistant ask your browser to unlock a door than handing the assistant a written copy of the key.

What can Gemini in Chrome access while auto browse is running?

The password itself is only one part of the security picture. Google says auto browse can access your local browsing state, including sites where you are already signed in. That means the agent may be able to interact with information and controls available inside those authenticated sessions.

Google also says Gemini may use personal information from connected services, such as Google Workspace, when that information is relevant to the task. When completing a task on a website, some of that information may be shared with the website if it is needed to complete what you asked for.

This is why the important question is not only “Can it read my password?” A signed-in browser session can already provide access to information that would normally be protected by a login.

The same principle applies when an AI is connected to email. In our guide on giving an AI agent access to Gmail, the larger risk is often what the agent can do with an authorized session, not whether it literally knows your Google password.

The biggest technical risk: prompt injection

Google identifies indirect prompt injection as a major threat for agentic browsers. This happens when malicious or misleading instructions are hidden inside content the AI reads, such as a webpage, an advertisement, an embedded frame, or user-generated content.

An attacker might try to make the agent ignore your original request and instead perform an unrelated action, reveal information, visit another site, or misuse an authenticated session.

Google gives examples of the type of harm it is trying to prevent, including an agent being manipulated into posting private information publicly, sending email data to an external service, or exposing information derived from connected apps.

This is one reason browser agents are a more difficult security problem than a normal chatbot. A chatbot can produce a bad answer. A browser agent may also be able to click, type, submit, sign in, and move information between services.

How Google tries to protect auto browse

Google uses several layers rather than relying on a single safety check.

1. Password Manager separation

Google Password Manager can help Chrome sign in, but Google says it does not give the password itself to Gemini. This reduces the chance that the model could expose stored credentials in a response or through a malicious webpage.

2. User confirmation before sensitive actions

Gemini may pause and ask for confirmation before actions such as sending communications, modifying data, submitting forms, scheduling events, accessing highly sensitive financial or health services, or using Password Manager to sign in.

3. Take over task

You can take control of the browser while Gemini is working. Google may also require you to take over for certain steps, including financial transactions, account creation, accepting terms, CAPTCHAs, or other actions where human control is important.

4. Origin restrictions

Google says Chrome uses an origin-based security design to limit which websites the agent can read from and which websites it can act on during a task. This is intended to reduce the chance that a compromised task can suddenly reach unrelated signed-in websites.

5. A separate alignment check

Google describes a separate “User Alignment Critic” model that reviews proposed actions independently from the main planning model. The purpose is to catch actions that do not match what the user actually asked Gemini to do.

Are these protections enough?

They reduce risk, but Google itself does not claim that auto browse is risk-free. Its help documentation says the feature is experimental and that safeguards do not guarantee protection against every mistake or attack.

Google specifically advises users to monitor important tasks and pay extra attention when Gemini is working with financial, legal, medical, work, email, or other sensitive information.

That is a useful way to think about agentic browsing in general: security controls can lower the probability of a bad action, but they do not remove the consequences if one happens.

What data does Gemini in Chrome process?

Google’s Gemini Apps Privacy Hub says Gemini in Chrome can process the URL and page content from the current tab and other tabs you share with it. If you use Gemini to find pages from your Chrome history, relevant URLs from your history can also be collected for that request.

Google also says information about sites you use with Gemini in Chrome, along with shared audio and files, can be stored in Gemini Apps Activity when the Keep Activity setting is enabled. Page content may also be logged temporarily to your Google Account even though it does not appear directly in the visible Gemini Apps Activity list.

For the latest details, check Google’s Gemini Apps Privacy Hub, because these policies can change as the feature develops.

How to check which sites Gemini can sign in to

On desktop Chrome, Google currently lets you review this in Google Password Manager:

  1. Open Chrome.
  2. Open Passwords and autofill.
  3. Open Google Password Manager.
  4. Select Settings.
  5. Look for Gemini can sign in for you.
  6. Review the sites you have allowed.
  7. Remove any site you no longer want Gemini to sign in to automatically.

You can also go to Chrome Settings → AI innovations → Gemini in Chrome and turn Let Gemini browse for you off if you do not want auto browse enabled.

How to use Gemini auto browse more safely

  1. Review the plan before starting. Make sure Gemini understood the task and is using the websites you expected.
  2. Do not grant sign-in access everywhere. Only approve Password Manager access for sites where it is genuinely useful.
  3. Watch sensitive tasks. Do not start a banking, medical, legal, or work-related task and assume the agent can safely run unattended.
  4. Read confirmation prompts. Do not approve a sign-in, message, form submission, purchase, or account change automatically.
  5. Use multi-factor authentication. A browser agent should not be your only security boundary.
  6. Keep Chrome updated. Agentic browsing security depends partly on browser-level protections that Google can improve through Chrome updates.
  7. Review connected apps. The more services an AI can access, the more data may be available during a task.
  8. Stop the task if its behavior changes unexpectedly. An unexpected website, request, or action is a reason to take over rather than continue.

If you use AI systems that connect to multiple apps and services, it is also worth understanding Model Context Protocol (MCP), because the same broader question appears there: how much authority should an AI agent receive, and how tightly should those permissions be scoped?

Who currently gets auto browse?

As of October 2026, Google says auto browse is still rolling out gradually. Current consumer requirements include being 18 or older, using an eligible Google AI Pro or Ultra account, signing in to Chrome, granting browser permission, and using supported Chrome settings. Availability also depends on region and platform, and the feature is not available in Incognito mode.

Because rollout conditions are changing quickly, Google’s live help page is more reliable than assuming every Gemini in Chrome user has the same features.

The key difference: password access vs account access

The most important takeaway is that Gemini does not need to know your password to do something important inside a logged-in account.

If Chrome can authenticate you and the agent can operate in that session, Gemini may be able to interact with the account within the permissions and safeguards of the task. That is why authenticated browser access deserves the same level of attention you would give any other powerful integration.

This is also why businesses evaluating AI agents should think in terms of permissions and blast radius rather than only credentials. Our guide to AI agents for small businesses explains where agent automation can help and where stronger controls are needed.

Final answer: can Gemini in Chrome use your saved passwords?

Gemini in Chrome can use Google Password Manager to help sign in to websites that you have approved, but Google says the actual saved password is not shared with Gemini and the model does not have direct access to your password vault.

The bigger security issue is what happens after sign-in. Auto browse can operate inside logged-in sessions, read task-relevant page content, and take actions across websites. Google has built confirmation prompts, origin restrictions, prompt-injection detection, a separate alignment checker, and take-over controls to reduce those risks—but Google also says users still need to monitor sensitive tasks.

So the practical rule is simple: use auto browse for convenience, but treat sign-in permissions and authenticated sessions as sensitive access. Grant them selectively, review what Gemini is doing, and take over whenever the task involves something you would not want an automated system to get wrong.

FAQ

Can Gemini in Chrome see my saved passwords?

Google says no. Google Password Manager does not share saved passwords with Gemini in Chrome, and Google’s Chrome security team says the model does not have direct access to stored passwords.

Can Gemini sign in to websites for me?

Yes, with your permission. Chrome can use Google Password Manager to sign in to sites that you have allowed Gemini to use.

Can Gemini access websites where I am already logged in?

Google says auto browse has access to the local browsing state relevant to the task, including sites where you are signed in.

What is the biggest risk with Gemini auto browse?

One major risk is indirect prompt injection, where malicious content on a webpage tries to manipulate the agent into taking an action that does not match your original request.

Can I stop Gemini from browsing for me?

Yes. In Chrome settings, open AI innovations, then Gemini in Chrome, and turn off the permission that lets Gemini browse for you. You can also remove individual sites from the list that Gemini is allowed to sign in to.