{"slug": "google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands", "title": "Google lets Gemini Spark use logged-in Chrome sessions for web errands", "summary": "Google announced on August 3rd that Gemini Spark, its personal AI agent, can now use Chrome's auto browse feature to complete multi-step web errands such as scheduling apartment viewings, researching flights, shopping, booking accommodations, making restaurant reservations, and arranging appointments, rolling out in the U.S. to Google AI Pro and Ultra subscribers. The integration leverages Chrome's signed-in sessions, preferences, and saved credentials, giving Google a competitive edge in the AI agent market. Google warns the feature is experimental and users remain responsible for its actions, while Chrome's security architecture includes a User Alignment Critic to mitigate prompt-injection risks.", "body_md": "[Google said in a thread on X](https://x.com/google/status/2084306026577244627?s=46) on August 3rd that Gemini Spark can use Chrome's auto browse feature to complete multi-step errands across websites where a user is already signed in.\n\n[https://x.com/google/status/2084306026577244627?s=46](https://x.com/google/status/2084306026577244627?s=46)\n\nWith permission, Spark can schedule viewings for saved apartments, research flights, shop, book accommodations, make restaurant reservations and arrange appointments. The integration is rolling out in the U.S. to Google AI Pro and Ultra subscribers, according to [Google's support documentation](https://support.google.com/gemini/answer/16821166).\n\nThe release gives Spark access to one of Google's most valuable advantages in the AI agent market: a browser that already holds a user's sessions, preferences and saved credentials. Google can combine Gemini with Chrome, Google Account and Password Manager instead of asking users to recreate that context inside a separate agent.\n\nThat advantage comes from infrastructure accumulated long after [Larry Page](https://engineering.stanford.edu/about/history/heroes/2014-heroes/larry-page) and [Sergey Brin](https://stvp.stanford.edu/people/sergey-brin) founded Google around web search in 1998. Chrome now gives Google a route from answering questions about the web to performing actions inside it.\n\n### Spark moves beyond app-by-app integrations\n\nGoogle introduced [Gemini Spark in its May 19th release notes](https://gemini.google.com/updates) as a personal agent that could work on users' behalf. On June 30th, Gemini app product director Adam Coimbra and Google DeepMind engineering vice president Srinivasan \"Cheenu\" Venkatachary [expanded Spark to macOS and added integrations](https://blog.google/innovation-and-ai/products/gemini-app/gemini-spark-updates-june-2026/) with services including Canva, Dropbox, Instacart, OpenTable and Zillow Rentals.\n\nChrome auto browse pushes that strategy onto the wider web. Google's documentation says Gemini can use sites even when the user has not connected the corresponding service to the Gemini app. Spark can work through a local Chrome browser, giving it access to the same signed-in sites as the user, or use a separate remote browser for some tasks.\n\nThe local connection is the important change. With explicit permission, Google Password Manager can help Spark sign in to a site without exposing the stored password directly to the model. Spark asks for confirmation before each browsing task, and users can watch its work, stop it or take control of the tab.\n\nThe agent may share information with third-party sites as it works, including contact details, files and preferences needed for a task. Google's help page also warns that Gemini can click the wrong control, add an incorrect item or quantity to a cart, or report that a task is complete when it is not. Google labels the agentic feature experimental and says users remain responsible for its actions.\n\n### Chrome carries the security burden\n\nGiving an AI agent access to signed-in browser sessions also raises the cost of a successful prompt-injection attack. Malicious instructions embedded in a page, advertisement, iframe or user review could attempt to divert an agent from the user's request or make it disclose information.\n\nGoogle says its [agentic Chrome security architecture](https://blog.google/security/architecting-security-for-agentic/) checks proposed actions with a separate User Alignment Critic that is isolated from untrusted page content. Chrome also restricts the agent to web origins deemed relevant to the task, scans pages for attempted prompt injection and requires user intervention around consequential actions.\n\nPayments, account creation, acceptance of terms and other sensitive steps may be handed back to the user. Chrome also seeks confirmation before sending communications, modifying data, submitting forms or scheduling events. Those checkpoints limit autonomy at the moment an agent can cause financial or reputational damage, while leaving research and navigation to Spark.\n\nGoogle's safeguards reduce exposure; Google does not claim they eliminate it. Its security team has described indirect prompt injection as the primary new threat for agentic browsers, and the support documentation warns that protections cannot guarantee against every harmful or unintended action.\n\n### Distribution becomes part of the agent product\n\nOpenAI's [ChatGPT agent](https://openai.com/index/introducing-chatgpt-agent/) operates through its own virtual computer and asks users to take over when authentication is required. Anthropic says [Claude can control a browser, mouse and keyboard](https://claude.com/blog/dispatch-and-computer-use) after receiving permission. Google's approach can start inside the browser where a user is already working and signed in.\n\nGoogle is placing that access behind its paid AI plans. Pro subscribers can request up to 20 multi-step Chrome tasks per day, while Ultra subscribers can request up to 200, according to Google's current support page. Users must be at least 18, use English in the U.S., sign into Chrome and enable standard or enhanced Safe Browsing.\n\nThe rollout also gives Spark a large potential funnel. Sundar Pichai said in [Alphabet's second-quarter remarks](https://blog.google/company-news/inside-google/message-ceo/alphabet-earnings-q2-2026/) that the Gemini app had reached 950 million monthly active users. That figure covers Gemini overall rather than Spark, but it shows the distribution Google can direct toward a paid agent feature.\n\nFor smaller agent developers, Chrome integration changes the competitive baseline. Browser state, identity, password permissions, payment handoffs and prompt-injection defenses now sit alongside model performance as core parts of a consumer agent. Google already owns most of those layers and can bundle them into the subscription carrying Gemini Spark.", "url": "https://wpnews.pro/news/google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands", "canonical_source": "https://runtimewire.com/article/google-gemini-spark-logged-in-chrome-web-errands", "published_at": "2026-08-03 17:07:22+00:00", "updated_at": "2026-08-03 17:26:38.269380+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-products", "ai-safety"], "entities": ["Google", "Gemini Spark", "Chrome", "Google AI Pro", "Google AI Ultra", "Google Password Manager", "Adam Coimbra", "Srinivasan \"Cheenu\" Venkatachary"], "alternates": {"html": "https://wpnews.pro/news/google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands", "markdown": "https://wpnews.pro/news/google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands.md", "text": "https://wpnews.pro/news/google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands.txt", "jsonld": "https://wpnews.pro/news/google-lets-gemini-spark-use-logged-in-chrome-sessions-for-web-errands.jsonld"}}