Close Menu
  • Home
  • AI
  • Education
  • Entertainment
  • Food Health
  • Health
  • Sports
  • Tech
  • Well Being

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

India’s Sarvam wants to bring its AI models to feature phones, cars and smart glasses

February 18, 2026

Indian AI lab Sarvam’s new models are a major bet on the viability of open-source AI

February 18, 2026

Moderna combo flu/COVID vaccine succeeds in mid-stage trial

February 18, 2026
Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise With Us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
IQ Times Media – Smart News for a Smarter YouIQ Times Media – Smart News for a Smarter You
  • Home
  • AI
  • Education
  • Entertainment
  • Food Health
  • Health
  • Sports
  • Tech
  • Well Being
IQ Times Media – Smart News for a Smarter YouIQ Times Media – Smart News for a Smarter You
Home » Google details security measures for Chrome’s agentic features
AI

Google details security measures for Chrome’s agentic features

IQ TIMES MEDIABy IQ TIMES MEDIADecember 8, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


An increasing number of browsers are experimenting with agentic features that will take actions on your behalf, such as booking tickets or shopping for different items. However, these agentic capabilities also come with security risks that could lead to loss of data or money.

Google detailed its approach to handling user security on Chrome using observer models and consent for user action. The company previewed agentic capabilities on Chrome in September and said these features will roll out in the coming months.

The company said it is using the help of a few models to keep agentic actions in check. Google said it built a User Alignment Critic using Gemini to scrutinize the action items built by the planner model for a particular task. If the critic model thinks that the planned tasks don’t serve the user’s goal, it asks the planner model to rethink the strategy. Google noted that the critic model only sees the metadata of the proposed action and not the actual web content.

A pair of screenshots showing what Chrome's agent model can see from a website.
Image Credits: Google

What’s more, to prevent agents from accessing disallowed or untrustworthy sites, Google is using Agent Origin Sets, which restrict the model to access read-only origins and read-writeable origins. Read-only origin is data that Gemini is permitted to consume content from. For instance, on a shopping site, the listings are relevant to the task, but banner ads aren’t. Similarly, Google said the agent is only allowed to click or type on certain iframes of a page.

“This delineation enforces that only data from a limited set of origins is available to the agent, and this data can only be passed on to the writable origins. This bounds the threat vector of cross-origin data leaks. This also gives the browser the ability to enforce some of that separation, such as by not even sending to the model data that is outside the readable set,” the company said in a blog post.

Google is also keeping a check on page navigation by investigating URLs through another observer model. This can prevent navigation to harmful model-generated URLs, the company said.

A screenshot showing Chrome's agent model asking user permission before paying for an item while shopping.
Image Credits: Google

The search giant said that it is also handing over the reins to users for sensitive tasks. For instance, when an agent tries to navigate to a sensitive site with information like banking or your medical data, it first asks the user. For sites that require sign-in, it’ll ask the user for permission to let Chrome use the password manager. Google said that the agent’s model doesn’t have exposure to password data. The company added that it will ask users before taking actions like making a purchase or sending a message.

Techcrunch event

San Francisco
|
October 13-15, 2026

Google said that, in addition to this, it also has a prompt-injection classifier to prevent unwanted actions and is also testing agentic capabilities against attacks created by researchers.

AI browser makers are also paying attention to security. Earlier this month, Perplexity released a new open-source content detection model to prevent prompt injection attacks against agents.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
IQ TIMES MEDIA
  • Website

Related Posts

India’s Sarvam wants to bring its AI models to feature phones, cars and smart glasses

February 18, 2026

Indian AI lab Sarvam’s new models are a major bet on the viability of open-source AI

February 18, 2026

Apple is reportedly cooking up a trio of AI wearables

February 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Shooting at South Carolina dorm leaves 2 dead, suspect charged with murder

February 17, 2026

Hawaii Bill Would Turn Kids Into Published Authors At Kalihi Schools

February 17, 2026

Gov. Newsom expanded free preschool. Now private daycares say they can’t afford to stay open

February 17, 2026

Michigan wants schools ready for cardiac emergencies, fails to provide funds

February 17, 2026
Education

Shooting at South Carolina dorm leaves 2 dead, suspect charged with murder

By IQ TIMES MEDIAFebruary 17, 20260

COLUMBIA, S.C. (AP) — A man has been charged with murder after taking part in…

Hawaii Bill Would Turn Kids Into Published Authors At Kalihi Schools

February 17, 2026

Gov. Newsom expanded free preschool. Now private daycares say they can’t afford to stay open

February 17, 2026

Michigan wants schools ready for cardiac emergencies, fails to provide funds

February 17, 2026
IQ Times Media – Smart News for a Smarter You
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • About Us
  • Advertise With Us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2026 iqtimes. Designed by iqtimes.

Type above and press Enter to search. Press Esc to cancel.