Google Chrome adds layered defenses for agentic AI browsing
Security Tool/Service
Summary
Hide ▲
Show ▼
Chrome is adding layered security features for agentic AI browsing, reducing the risk that indirect prompt injection can steer browser actions or leak data. The update centers on a User Alignment Critic and Agent Origin Sets, which constrain what the agent can see and do. It also adds explicit approval gates for sensitive sites and actions such as banking, healthcare, purchases, and payments.
Related Happenings
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
**Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: **Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Gemini Enterprise Agent Platform launch adds agent identity, policy enforcement, and anomaly detection controls
Security Tool/Service
First: 23.04.2026 15:00
Last: 23.04.2026 15:00
Sources 1
About this happening:
Google Cloud expanded **Gemini Enterprise Agent Platform** with new security controls for **AI agents**, giving organizations more visibility and policy enforcement for autonomous...
Gemini Enterprise Agent Platform launch adds agent identity, policy enforcement, and anomaly detection controls
Security Tool/ServiceAbout this happening: Google Cloud expanded **Gemini Enterprise Agent Platform** with new security controls for **AI agents**, giving organizations more visibility and policy enforcement for autonomous...
Google expands Gemini AI for malicious ad blocking on Google Ads
Security Tool/Service
First: 16.04.2026 18:24
Last: 16.04.2026 18:24
Sources 1
About this happening:
**Google** expanded **Gemini AI** use across its ad platforms to detect and block **malicious ads** in real time, reducing scam and malvertising exposure at scale. The move matter...
Google expands Gemini AI for malicious ad blocking on Google Ads
Security Tool/ServiceAbout this happening: **Google** expanded **Gemini AI** use across its ad platforms to detect and block **malicious ads** in real time, reducing scam and malvertising exposure at scale. The move matter...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The **Venom Stealer** **malware-as-a-service** platform has been identified as a **credential-theft** threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The **Venom Stealer** **malware-as-a-service** platform has been identified as a **credential-theft** threat that keeps exfiltrating data after infection, extending the window for...
LayerX font-rendering PoC exposes a browser-rendering gap in AI assistant analysis
Technical Analysis
First: 17.03.2026 15:59
Last: 17.03.2026 15:59
Sources 1
About this happening:
A **LayerX** proof-of-concept showed that a **font-rendering attack** can hide malicious webpage commands from AI assistants, creating a risk of **unsafe guidance** when the brows...
LayerX font-rendering PoC exposes a browser-rendering gap in AI assistant analysis
Technical AnalysisAbout this happening: A **LayerX** proof-of-concept showed that a **font-rendering attack** can hide malicious webpage commands from AI assistants, creating a risk of **unsafe guidance** when the brows...
Timeline
-
09.12.2025 13:14 2 articles · 5mo ago
Google announces Chrome defenses for agentic AI browsing
Initial DisclosureGoogle announced layered defenses in Chrome for agentic AI browsing to reduce indirect prompt injection risk from untrusted web content, including the User Alignment Critic, Agent Origin Sets, user approval gates for sensitive sites and actions, page-level prompt-injection checks, Safe Browsing, on-device scam detection, and a bounty of up to $20,000 for demonstrations that break the security boundaries.
Show sources
- Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats — thehackernews.com — 09.12.2025 13:14
- Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats — thehackernews.com — 09.12.2025 13:14