Google has introduced an enhanced autofill feature in Chrome that allows users to store and automatically fill in sensitive personal information, including driver's license numbers, passport numbers, and vehicle identification details such as license plates and VINs. The feature is opt-in, requiring users to manually enable it, and Google emphasizes that all stored data is encrypted and only used with explicit user confirmation. The update aims to streamline the process of completing complex online forms and is rolling out globally across all languages, with support for additional data types expected in the future.
While the convenience of this feature is clear, security experts have raised concerns about the risks of concentrating sensitive information in a single location. Although Google asserts that users remain in full control of their data and that strong privacy protections are in place, experts warn that a compromised Google account could expose not only emails but also any personal information stored via autofill. The recent exposure of millions of Gmail-linked credentials, though unrelated to autofill, highlights the broader risks of storing sensitive data online and underscores the need for users to carefully weigh convenience against potential security consequences.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
Google expanded Chrome Autofill to support storing and filling sensitive identity and vehicle information, including passports, driver's licenses, and vehicle details. Multiple reports on November 4, 2025 described the rollout and raised questions about the security implications of keeping such data in the browser.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcezdnet.com
Open sourcetechrepublic.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.