Google Chrome AI Agent Poses Security Risk to User Sessions
TL;DR. Google's autonomous AI agent, Spark, can navigate Chrome using logged-in user sessions, raising security concerns despite built-in defenses. - Spark's auto-browse feature requires access to active session cookies and stored payment methods. - This agentic browsing capability is currently a US-only preview for AI Pro/Ultra subscribers. - The article highlights the trust required to grant an AI agent full control over a browser session.
- Google's Spark AI agent offers 'auto browse' in Chrome, accessing logged-in user sessions.
- The feature handles sensitive data like session cookies and payment methods.
- Concerns exist about the trust required to give an AI agent control over browsing.
- Chrome's auto browse is a US-only preview for specific Google AI subscribers.
- Google has integrated defenses, but the article suggests they are not foolproof.
Sources
- I finally understand why handing an AI agent your Chrome session is terrifying — androidpolice.com
- arstechnica.com — arstechnica.com