BIP America News & Media Platform

collapse
Home / Daily News Analysis / Chrome is putting things on your computer you never agreed to

Chrome is putting things on your computer you never agreed to

Jun 30, 2026  Twila Rosenbaum  62 views
Chrome is putting things on your computer you never agreed to

Your browser has been busy on your behalf, often without asking. Two recent incidents highlight how Chrome can place files and programs on your computer without your explicit agreement. One comes from Google itself, quietly downloading a large AI model. The other from cybercriminals posing as a legitimate AI search tool. Both exploit the same trust you place in your browser, and both raise serious questions about consent in the digital age.

Chrome runs on billions of devices worldwide, making it one of the most powerful software platforms ever created. This reach also makes it an attractive target for silent installations, whether by the company that makes it or by attackers looking to hijack your data. Two stories from the past few days illustrate the problem from both sides: a legitimate vendor normalizing hidden downloads and a malicious actor mimicking AI tools.

Google's 4GB houseguest

Since at least April, Chrome has been quietly downloading Gemini Nano, Google's on-device AI model, onto eligible laptops and desktops. The file is about 4GB, roughly the size of a high-definition movie. It arrives with no prompt, no notification, and no obvious way to stop it. According to reports, users who delete the model may find Chrome fetches it again during a regular update.

The model powers on-device features such as scam detection and writing assistance. The catch is that most people never asked for it and never knew it landed. Privacy researcher Alexander Hanff, writing as "That Privacy Guy", caught the install on a fresh Mac profile that had received zero human input. Using the system's own file-event log, he documented the 4GB model unpacking itself in about 14 minutes while a tab sat idle. He argues that the silent push breaches Europe's ePrivacy Directive and the General Data Protection Regulation (GDPR), which require explicit consent before storing non-essential data on user devices. The bandwidth consumed by millions of such downloads also carries a heavy climate cost at billion-device scale.

Google says the model removes itself if a device runs short on storage or battery. The company also points out that since February, users can turn it off in Chrome settings under System and then on-device AI options. After that, it stops downloading. But the default remains on, and many users never explore settings.

There is a twist that muddies trust further. The visible "AI Mode" pill in the address bar does not use the on-device model at all. Those queries go to Google's servers. So the user pays the storage and bandwidth cost of a local model, while the headline AI feature still sends typing to the cloud. This disconnect undermines Google's argument that the local model benefits users directly.

Historical context of silent installs

Google is not alone in pushing software updates without clear consent. Browser vendors have long used background updaters to patch security flaws automatically. However, the Gemini Nano case crosses a line because the download is not a security fix – it's a functional add-on that consumes significant resources. Similar controversies have occurred with Adobe Flash updates and Microsoft's Windows 10 upgrades, but those at least had more prominent opt-out mechanisms. Chrome's approach is exceptionally quiet, relying on technical toggles rather than user-facing consent dialogues.

The ePrivacy Directive has specific rules about storing information or gaining access to information already stored in a user's device. Exceptions apply only for the sole purpose of carrying out transmission of a communication or strictly necessary for providing a service explicitly requested by the user. Installing a 4GB AI model is neither. Legal experts suggest that Google may face fines if regulators investigate.

The impostor in the address bar

The second story is darker because the actor was not Google. Microsoft's threat researchers found a malicious Chrome extension dressed up as the AI search engine Perplexity. It quietly logged what people searched for, then forwarded them to real results so nothing looked wrong. The extension, called "Search for perplexity ai", used a look-alike domain (perplexity-ai[.]info instead of perplexity.ai) to pass for the real thing. Once installed, it made itself the default search engine. Every query and every character typed into the address bar went first to an attacker-controlled server, which logged it with your IP address and browser fingerprint.

The theft happened on that first hop, before the redirect. The extension abused Chrome's network-rule permissions (declarativeNetRequest) to intercept and redirect traffic. Microsoft's analysis revealed server-side code that recorded each request in a detailed log. Google removed the extension after the disclosure, but not before it had possibly compromised many users.

This was not a one-off. Microsoft earlier tied a wave of AI-branded extensions to roughly 900,000 installs across more than 20,000 corporate networks, harvesting ChatGPT and DeepSeek chat histories. The AI label gets the install; the permissions do the damage.

Same surface, different intruder

Put the two together and a pattern emerges. The browser, and the address bar in particular, has become a trust surface that both vendors and attackers want to occupy. Google treats your disk as a delivery target for its own AI. A criminal treats your omnibox as a wiretap. The user sits in the middle, rarely asked for permission. This convergence should worry anyone who cares about trust in everyday software. When a legitimate company normalizes silent installs, it gets harder for users to spot malware doing something similar. Consent stops being a habit. The line between a feature and an intrusion blurs.

The timing is also critical. AI branding today is a magnet. People associate AI tools with usefulness, so they click without hesitation. Attackers know this, and the same instinct that makes us try a shiny new assistant makes us wave through malicious apps wearing the same costume. The Perplexity impostor is a textbook example: it rode the AI wave to gain access to users' most intimate data – their search queries.

What you can do to protect yourself

A few minutes of housekeeping can significantly reduce your exposure. On Chrome, open Settings, then System, and turn off on-device AI if you do not want the Gemini Nano model. You can also check for a folder named OptGuideOnDeviceModel in your Chrome profile directory (typically ~/Library/Application Support/Google/Chrome/OptGuideOnDeviceModel on macOS) to see whether the 4GB file is already present. If it is, deleting it will reclaim space, but Chrome may redownload it unless you disable the setting.

Next, audit your extensions. Remove anything you do not recognize. Check the publisher name and the exact domain before installing AI-branded tools. Always hover over links or manually type the known domain. Watch for a search engine that has suddenly changed – this is a common sign of a hijacking. Also review the permissions each extension requests; if an AI helper asks to read all data on all websites, that's a red flag.

For added protection, consider using a separate browser profile for high-risk activities like searching with AI tools, or use a dedicated security extension that blocks suspicious redirects. However, be aware that too many extensions can themselves become a security risk.

None of this is technically complex. It is simply the price of using a browser that increasingly acts on its own. The deeper fix is not yours to make. It belongs to the company that decides whether the default browser asks before it acts. Until that changes, the safest assumption is simple: your privacy is your job, and the browser is not always on your side. The consent crisis in Chrome is a symptom of a broader industry trend where convenience trumps permission. Users must remain vigilant, because the tools they trust increasingly operate on their own agenda.


Source: TNW | Artificial-Intelligence News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy