Google is testing deeper Gemini integration in Chrome via a new internal feature called “Skills,” which appears to let users define named, instruction-based automations that Gemini can execute inside the browser. The feature is surfaced through a new chrome://skills page and aligns with Google’s stated direction of turning Gemini into a more agent-like assistant capable of acting across tabs and, over time, integrating more tightly with Google services.
Separately, Google has added user controls to manage the on-device GenAI model used by Chrome’s Enhanced Protection (Safe Browsing) capabilities, which were previously upgraded with AI for “real-time” detection of dangerous sites, downloads, and potentially malicious extensions. In Chrome Canary, users can disable On-device GenAI under Chrome → Settings → System, which also enables deletion of the local model; Google indicated the local model may support additional security and browser features beyond scam detection as it rolls out more broadly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A report alleged that Google Chrome had been silently downloading roughly 4GB of Gemini Nano on-device model files to Windows, Apple Silicon, and Ubuntu systems without explicit user consent, and would re-download them after deletion. The files were reportedly tied to local Chrome AI features and raised privacy, bandwidth, and compliance concerns.
Google announced Chrome Enterprise updates that add Gemini-powered Auto Browse for eligible Workspace users in the US, letting the browser perform multi-step actions across tabs with user approval. The release also brings Skills to Chrome Enterprise and adds new admin security features, including AI usage visibility, risky extension controls, Gemini Summary, Okta-backed session protections, and remote clearing of browsing data on compromised devices.
Google launched the Chrome 'Skills' feature, allowing users to save Gemini prompts as reusable workflows and run them on the active page or across multiple tabs from the browser side panel. The rollout started for signed-in desktop users on Windows, macOS, and ChromeOS using English, alongside a Skills Library of prebuilt workflows and manual confirmation for sensitive actions.
Google Chrome now exposes a user-facing setting in Chrome Canary to turn off 'On-device GenAI,' allowing users to disable and delete local AI models used for features including scam detection. Broader rollout is expected later.
References to an internal chrome://skills page show Google is testing a new 'Skills' capability that would let users define named task instructions for Gemini to execute in Chrome. The feature appears to be under internal testing with no public rollout timeline announced.
Google previously said it plans to turn Gemini in Chrome into a more agentic assistant over the coming months, with future capabilities such as helping users re-find pages and interact with Google apps without switching tabs.
Google started rolling out Gemini in Chrome on desktop in the United States, where it functions as an in-browser helper for explaining, summarizing, and comparing information across tabs.
Google upgraded Chrome’s Enhanced Protection safe browsing feature with AI capabilities last year, adding real-time protection against dangerous websites, downloads, and extensions, including deeper scanning of suspicious downloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcezdnet.com
Open sourceghacks.net
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.