Forget camera and location pop-ups. The permission prompt that matters most on your computer now is the one where an AI assistant asks to drive your browser — logins, saved passwords, open tabs and all. Those prompts are showing up everywhere lately. And the past few months handed us a very clear preview of what happens when this goes wrong.
What you're actually granting
Google's Gemini Spark added an auto-browse mode for Chrome that can use the accounts you're signed into and the passwords Chrome has saved — to book things, buy things, fill forms, "run errands," as Digital Trends puts it. It's permission-gated, not on by default, which counts for something. OpenAI's heading the same way: the ChatGPT Chrome extension and desktop app can now read your open tabs, react to text you highlight, and answer questions about the YouTube video you're watching.
Understand the shift here. A website sees one slice of your life. An agent with your logins sees everything you can see — and can do things as you.
This isn't theoretical
In January, two Chrome extensions got caught stealing ChatGPT and DeepSeek conversations from about 900,000 people. Full chat contents, plus every open tab URL, shipped to a remote server every 30 minutes, The Hacker News reported. The consent screen? It asked to collect "anonymous, non-identifiable analytics data."
Same month, Google patched CVE-2026-0628 in Chrome 143. Until that fix, SecurityWeek reports, a bad extension could inject code straight into Chrome's Gemini Live panel — puppeting the assistant you thought you were talking to.
Palo Alto's Unit 42 team spelled out why attackers love this territory: we paste our most sensitive stuff into AI chats. Code. Draft emails. Plans. An extension wedged between you and the AI intercepts material worth far more than the browsing history old-school malware scraped.
Four checks before you hit Allow
One: verify who made it. Spark and the ChatGPT extension are first-party tools. Every incident above involved third-party extensions cosplaying as AI helpers. Check the publisher before installing anything that touches your chats.
Two: treat password access as the bright line. Reading a page is tier one. Logging in as you is tier two. Grant tier two only for accounts you'd hand to a human assistant without flinching.
Three: audit what's already in your browser. Anything with "read data on all sites" can read your AI conversations too. If you can't vouch for it, out it goes.
Four: don't trust the consent screen's self-description. "Anonymous analytics" was the cover story for a 900,000-user chat heist. Publisher and permissions tell the truth; marketing copy doesn't.
The trade, plainly
Researchers following agentic browsing keep landing on the same point: these tools are useful precisely because they're deep, and risky for the same reason. The assistants aren't the scandal. The access model is the new attack surface. Sometimes the errand is worth it — just know exactly what you're handing over when you say yes.
Image: Dan Nelson, via Pexels





