Gemini Spark now has Chrome web-browsing capabilities

← Back to the feed

Gemini Spark now has Chrome web-browsing capabilities

Engadget · 2 hours ago

Google has integrated its agentic AI assistant, Gemini Spark, with the Chrome web browser, allowing it to carry out tasks online using a user's logged-in accounts and saved passwords. Once signed in to Chrome, Spark can handle what Google describes as "tedious web errands," such as researching flights and beginning the booking process, or arranging viewings for flats. The move marks a significant step in AI assistants taking on more autonomous, hands-on roles in everyday browsing tasks, though it raises fresh questions about security given the access being granted.

Google has acknowledged the risks of handing over passwords and account access to an AI tool, pointing to safeguards against "prompt injection" attacks, where hidden instructions on malicious websites try to manipulate the assistant into harmful actions like unauthorised payments or data theft. The company says it is using a "layered defense" combining deterministic and probabilistic measures, though it has not detailed exactly how these work. As a safety measure, Spark will not complete purchases automatically, leaving the final review and confirmation to the user. The Chrome integration is rolling out now in the US, with other regions to follow, alongside a wider expansion of Spark access to Google AI Pro subscribers in more than 160 countries.

  • Gemini Spark can now browse Chrome using saved logins and passwords
  • It can research flights and property viewings, but not pay
  • Rolling out in the US first; Spark access expanded to 160+ countries

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Advocates of this feature argue that letting an AI assistant use logged-in sessions and saved passwords to complete routine web tasks removes genuine friction from everyday life, saving time on form-filling, bookings and other repetitive chores. They point out that users retain choice over whether to grant this access, and that entrusting a well-resourced company with strong security practices to manage credentials may be safer than users reusing weak passwords or copying them manually across sites. For this camp, the benefit of automation outweighs the marginal risk, provided permissions and oversight are clear.

The case against

Critics caution that granting an AI agent access to saved passwords and active sessions meaningfully expands the attack surface, since a single flaw in the assistant's browsing logic or a prompt-injection exploit on a malicious webpage could let sensitive accounts be misused without the user's knowledge. They emphasise that trust in credential handling has historically been reserved for the browser and the user alone, and that delegating authenticated actions to an automated agent introduces new failure modes – mistaken purchases, leaked data, or unintended account changes – that are hard to audit after the fact. For this group, convenience should not come before rigorous, independently verified safeguards.

AI Americas Technology World

Read the full article at the source →