Close Menu
  • Home
  • AI
  • Entertainment
  • Finance
  • Sports
  • Tech
  • USA
  • World
  • Latest News

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

What's Hot

Trump’s first veto hits bipartisan infrastructure project

January 1, 2026

Russia-Ukraine: Putin exudes confidence as Russia approaches tough milestone

January 1, 2026

AFCON 2025: Who will play in the Round of 16? Everything you need to know | Africa Cup of Nations News

January 1, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Vimeo
BWE News – USA, World, Tech, AI, Finance, Sports & Entertainment Updates
  • Home
  • AI
  • Entertainment
  • Finance
  • Sports
  • Tech
  • USA
  • World
  • Latest News
BWE News – USA, World, Tech, AI, Finance, Sports & Entertainment Updates
Home » Google details security measures for Chrome’s agent function
AI

Google details security measures for Chrome’s agent function

adminBy adminDecember 8, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Share
Facebook Twitter LinkedIn Pinterest Email


More and more browsers are experimenting with agent features that perform actions on your behalf, such as booking tickets or shopping for various items. However, these agent features also come with security risks that can lead to loss of data and money.

Google detailed its approach to handling user security in Chrome using the observer model and user action consent. The company previewed agent features on Chrome in September and said these features will be rolled out in the coming months.

The company said it utilizes several models to constrain agent actions. Google said it built the User Alignment Critic using Gemini to vet action items built by planner models for specific tasks. If the critic model determines that the planned task is not achieving the user’s objectives, it asks the planner model to reconsider its strategy. Google pointed out that the critic model only looks at the metadata of the proposed action, not the actual web content.

Two screenshots showing what Chrome's agent model can see from a website.
Image credit: Google

Additionally, to prevent agents from accessing unauthorized or untrusted sites, Google uses agent origin sets. This restricts the model to access read-only and read-write origins. Read-only origins are data that Gemini is allowed to consume content from. For example, on a shopping site, lists are task-related, but banner ads are not. Similarly, Google said agents are only allowed to click or enter specific iframes on pages.

“This boundary forces that only data from a limited set of origins is available to the agent, and that this data is passed only to writable origins. This limits the threat vector of cross-origin data leakage. It also gives browsers the ability to enforce some of the isolation, such as not even sending data outside of the readable set to the model,” the company said in a blog post.

Google also continues to check page navigation by inspecting URLs through a separate observer model. The company says this prevents navigation to harmful URLs generated by the model.

Screenshot showing Chrome's agent model asking users for permission before paying for items while shopping.
Image credit: Google

The search giant also said it is handing the reins of sensitive tasks to users. For example, when an agent attempts to navigate to a sensitive site containing information such as banking or medical data, it first asks the user questions. For sites that require sign-in, ask users for permission to use a password manager in Chrome. Google said this agent model is not exposed to password data. The company added that it asks users questions before taking actions such as making a purchase or sending a message.

tech crunch event

san francisco
|
October 13-15, 2026

In addition to this, Google said it also has a prompt injection classifier to prevent unwanted actions, and is also testing agent functionality against attacks created by researchers.

AI browser makers are also paying attention to security. Earlier this month, Perplexity released a new open-source content detection model to prevent instant injection attacks against agents.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleApple’s chip chief denies rumors of leaving the company, says he has no plans to leave the company
Next Article Stock Market Today: Live Updates
admin
  • Website

Related Posts

‘College dropout’ has become the most coveted qualification to be a startup founder

January 1, 2026

Investors predict AI will enter the workforce in 2026

December 31, 2025

My phone went off. Please live long. . . What exactly?

December 31, 2025

Best AI-powered dictation apps of 2025

December 30, 2025
Leave A Reply Cancel Reply

Our Picks

Newly freed hostages face long road to recovery after two years in captivity

October 15, 2025

Former Kenyan Prime Minister Raila Odinga dies at 80

October 15, 2025

New NATO member offers to buy more US weapons to Ukraine as Western aid dwindles

October 15, 2025

Russia expands drone targeting on Ukraine’s rail network

October 15, 2025
Don't Miss
Entertainment

Prediction of zodiac signs in 2026

By adminJanuary 1, 20260

Scorpio (October 23-November 21): “Jupiter (planet of expansion) moves into Leo on June 30, activating…

Little People, Big World’s Matt Roloff and Zach Roloff reunite amid feud

January 1, 2026

David Beckham pays tribute to Brooklyn Beckham amid family rift

January 1, 2026

Bruce Willis, Emma Heming Willis celebrate anniversary of relationship amid dementia

January 1, 2026
About Us
About Us

Welcome to BWE News – your trusted source for timely, reliable, and insightful news from around the globe.

At BWE News, we believe in keeping our readers informed with facts that matter. Our mission is to deliver clear, unbiased, and up-to-date news so you can stay ahead in an ever-changing world.

Our Picks

Russia-Ukraine: Putin exudes confidence as Russia approaches tough milestone

January 1, 2026

Live updates: Fire at ski resort in Crans-Montana, Switzerland, dozens believed dead in New Year’s disaster

January 1, 2026

Queen Camilla speaks publicly for the first time about train attack as a teenager

January 1, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact US
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2026 bwenews. Designed by bwenews.

Type above and press Enter to search. Press Esc to cancel.