Gemini Spark drives desktop Chrome using your logged-in accounts and saved passwords
Google's Spark agent can now operate desktop Chrome directly — booking property viewings, preparing flight searches — using the browser's existing sessions and stored credentials, and handing control back to the user at payment.
Handing control back at payment is the interesting design decision, because it is an admission about everything before payment. The agent is trusted to act as you right up to the point where a mistake becomes financially irreversible, and the boundary is drawn at money rather than at authority.
Operating the real browser rather than a headless one solves the hardest practical problem in agentic web use. Sites break automation deliberately, sessions expire, logins are gated behind device checks. An agent inside the browser you already use inherits all of that state and none of the fight.
It also inherits the credentials. Every saved password, every authenticated session, every service that trusts that browser profile — an agent driving it has the union of your access, scoped by nothing except what it decides to do next. That is a categorically different security posture from an API key with defined permissions.
Prompt injection is the specific exposure and it remains structurally unsolved: a web page the agent reads is untrusted input, and this agent reads pages while holding your session cookies. The payment handoff limits the worst financial outcome. It does nothing about the other things a logged-in browser can do.
AI Agent Store — AI Agents News — Week of August 14, 2026 → · Agentic.ai — Agentic AI News — August 2026 Launches, Models & Research →