started · updated
Chrome Sync Exploited for Silent Surveillance, Security Firm Finds
A security research firm, Certo, reported that cybercriminals can abuse Google Chrome's synchronization feature to covertly monitor a victim's online activity. By gaining temporary access to a device or compromising a Google account, an attacker can add their own account to Chrome and enable silent sync, capturing browsing history, searches, bookmarks, autofill data, and open tabs without alerting the user. The technique does not require sophisticated malware and can be used for cyberstalking, domestic digital abuse, and targeted espionage, allowing perpetrators to build detailed profiles of victims over weeks or months.
Users are advised to protect their Google accounts with strong passwords, enable two‑factor authentication, regularly review connected devices, and disable sync on shared or public computers to mitigate the risk of such silent surveillance.