Google's Gemini Spark now opens Chrome on its own, signs in with the passwords saved in the browser, moves from page to page, and stops before a payment for a person to approve. Google's own examples are ordinary errands: compare flight options and begin the booking, or schedule viewings for saved apartment listings. The feature is called Chrome auto browse, it asks permission before it starts, and it comes with the Google AI Pro subscription at about $20 a month, or AI Ultra above it.
Permission to use one saved password is permission to act as the account holder on that site. An agent working inside a live Chrome session can reach whatever the person at that machine can reach: the supplier portal, the invoicing system, the email account where password resets arrive.
Google says it has added protections against prompt injection, the trick where instructions hidden in a webpage, invisible to the person reading it, tell an agent to do something its owner never asked for. Brave's security researchers showed how well that works in August 2025, when text hidden in a Reddit comment made Perplexity's Comet browser act inside the user's logged-in accounts and give up private information.
Spark runs in Google's cloud, so the job carries on after the laptop is closed or the phone is locked.
Chrome auto browse is running in the United States first. Spark itself, which Google's July update page calls available worldwide, still does not run in the European Economic Area, the United Kingdom, Switzerland or Nigeria, by the footnote on that same page.