The usual synchronization feature in Google Chrome can imperceptibly turn the browser into a surveillance tool. To do this, the attacker does not need malware or technical skills - it is enough to access someone else's phone for a few minutes and connect your own Google account to the browser.
This scheme drew the attention of Certo specialists after a series of appeals from people who have faced digital control from partners. In one case, the woman was looking for a family lawyer and read a website for helping victims of abuse by a partner, and two days later, the partner told her what pages she opened and at what time.
The woman used only her phone and did not notice new apps. However, earlier the partner briefly received the device in hand, opened Chrome and entered the browser under his own account of Google. After it has enabled the synchronization, the visitor history of the beginning is automatically transmitted to his profile.
The owner of such an account can open Chrome on another phone or computer and view a synchronized story from anywhere in the world. He doesn't need a victim password. The warning about the new input is also not received by the owner of the device, but by the owner of the added account.
The danger is not limited to the list of visited sites. Chrome can also sync bookmarks, open tabs, auto-exposure data, and passwords saved. If a person after an attacker connects someone else's profile, saves the password from the site, the attacker will be able to see it on his device and try to grab other accounts.
Chrome does not show a noticeable warning that a new profile has appeared in the browser or has earned synchronization. Many users do not check at all which account is connected to the application. According to StatCounter, in June 2026, Chrome occupied 69.65% of the global browser market, so a simple scheme potentially affects millions of people. A similar method works not only on smartphones, but also on computers with Windows and macOS.
Certo offers Google to add a temporary notification when connecting a new account and constantly showing which profile the browser is synchronized with. Such clues would help the device owner to notice extraneous access faster without interfering with the usual work of Chrome.
You can check the connected profile in the browser settings. On the iPhone and iPad, the account address is displayed at the top of the settings section. On Android, Windows and macOS, it can be seen after clicking on the profile icon. An unfamiliar account should be deleted, and passwords from important services should be changed, especially if they were stored in Chrome.
For confidential searches, you can also use the incognito mode, since the pages visited do not fall into a synchronized story. The phone itself is better to protect with complex code and biometrics, and in the settings it is worth checking whether other people's fingerprints or facial recognition data have been added. The main feature of the scheme is that the usual browser function allows you to monitor a person almost without signs and without installing a spy application.
This scheme drew the attention of Certo specialists after a series of appeals from people who have faced digital control from partners. In one case, the woman was looking for a family lawyer and read a website for helping victims of abuse by a partner, and two days later, the partner told her what pages she opened and at what time.
The woman used only her phone and did not notice new apps. However, earlier the partner briefly received the device in hand, opened Chrome and entered the browser under his own account of Google. After it has enabled the synchronization, the visitor history of the beginning is automatically transmitted to his profile.
The owner of such an account can open Chrome on another phone or computer and view a synchronized story from anywhere in the world. He doesn't need a victim password. The warning about the new input is also not received by the owner of the device, but by the owner of the added account.
The danger is not limited to the list of visited sites. Chrome can also sync bookmarks, open tabs, auto-exposure data, and passwords saved. If a person after an attacker connects someone else's profile, saves the password from the site, the attacker will be able to see it on his device and try to grab other accounts.
Chrome does not show a noticeable warning that a new profile has appeared in the browser or has earned synchronization. Many users do not check at all which account is connected to the application. According to StatCounter, in June 2026, Chrome occupied 69.65% of the global browser market, so a simple scheme potentially affects millions of people. A similar method works not only on smartphones, but also on computers with Windows and macOS.
Certo offers Google to add a temporary notification when connecting a new account and constantly showing which profile the browser is synchronized with. Such clues would help the device owner to notice extraneous access faster without interfering with the usual work of Chrome.
You can check the connected profile in the browser settings. On the iPhone and iPad, the account address is displayed at the top of the settings section. On Android, Windows and macOS, it can be seen after clicking on the profile icon. An unfamiliar account should be deleted, and passwords from important services should be changed, especially if they were stored in Chrome.
For confidential searches, you can also use the incognito mode, since the pages visited do not fall into a synchronized story. The phone itself is better to protect with complex code and biometrics, and in the settings it is worth checking whether other people's fingerprints or facial recognition data have been added. The main feature of the scheme is that the usual browser function allows you to monitor a person almost without signs and without installing a spy application.