Researchers and victim-support advocates warned that cyberstalkers are exploiting Google Chrome Sync as a covert surveillance method, allowing abusers to monitor a victim’s browsing activity without installing malware or obtaining the victim’s Google credentials. The technique requires only brief physical access to a phone or computer: an abuser signs Chrome into a Google account they control, enables sync, and can then remotely review browsing history and potentially other synced data. Certo Software said the method can expose visits to sensitive resources such as family lawyers or domestic violence support sites, making it particularly dangerous in coercive-control and domestic abuse cases.
The reported abuse affects Chrome across Android, iPhone, Windows, and Mac, and researchers said it is harder for victims to detect because Chrome does not provide prominent in-app warnings when a new account is added or sync is enabled. Certo said stronger mobile protections and app-store enforcement against stalkerware may be pushing abusers toward misuse of legitimate built-in features instead of traditional spyware. The company urged users to review which account is signed into Chrome, remove unknown accounts, and change important passwords if saved credentials may have been synced, while calling on Google to provide clearer and more persistent notifications around account changes and sync activation.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
CyberScoop reported on Certo's findings and described how abusers can sign Chrome into an attacker-controlled Google account and enable sync to spy on victims' browsing activity. The report highlighted a case example involving monitoring of visits to a family lawyer and domestic violence support website.
Certo Software reported that cyberstalkers are abusing Google Chrome's sync feature to monitor victims after brief physical access to a device, without installing traditional spyware. The technique can expose browsing history and potentially synced data such as saved passwords across mobile and desktop platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcecertosoftware.com
Open sourcegs.statcounter.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.