Cyberstalkers Are Exploiting Chrome Sync to Spy on Victims
Published:
Emma* (not her real name) thought she’d finally found a way out. Late one night, while her partner was asleep, she spent twenty minutes searching for a family lawyer and reading through a domestic abuse support website, careful to close the tabs afterwards.
Two days later, her partner brought it up. He knew which website she’d visited and exactly when.
Emma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone. What she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own.
From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.
Certo has received a growing number of reports describing exactly this scenario. Our research team investigated, and what we found is a strikingly simple technique that requires no hacking skill, no malware, and no spyware app of any kind — just a few unattended minutes with someone’s phone and a feature that Google built for convenience.
A Shift Away From Spyware
Modern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be.
As a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain — just a quiet misuse of a feature the victim never knew existed.
The Chrome sync technique is one of the clearest examples of this shift yet, and it’s arguably more concerning than most because of just how popular Chrome is.
Chrome Sync: Built for Convenience, Not Scrutiny
Chrome’s sync feature exists to make life easier. Sign in with a Google account, and Chrome will keep your bookmarks, open tabs, browsing history, autofill data, and saved passwords in step across every device you use — your phone, tablet, laptop, whatever you’re signed into.
It’s a genuinely useful feature. It’s also, as we discovered, remarkably easy to turn into a surveillance tool.

Fig 1. Synced data on a Google Account
How the Attack Works
- The attacker gets brief physical access to the victim’s phone. This is the only hands-on step required, and it can take less than a minute.
- They open the Chrome app and add a Google account under their control — either their own personal account or one created specifically for this purpose.
- They make sure sync is switched on for that account, so browsing history (and, by default, much more) is set to sync automatically.
- The victim carries on using their phone as normal. From this point, their browsing activity is copied to the attacker’s Google account in the background.
- The attacker opens the same Google account on their own device and reviews the victim’s browsing history whenever they choose, from anywhere with an internet connection.
Because the attacker signs in with an account they already control, they never need to know the victim’s Google password. And because it’s the attacker’s account that’s new — not the victim’s — any “new sign-in” security alert Google sends goes straight to the attacker’s inbox, not the victim’s.

Fig 2. Browsing a website in Chrome (left) and viewing that browsing history on another device (right).
A Threat at Scale
Chrome isn’t a niche browser. According to StatCounter’s Global Stats, Chrome held 69.65% of the worldwide browser market share as of June 2026 — comfortably ahead of every other browser combined. It’s the default browser on most Android phones and one of the most-downloaded apps on iPhone.
That scale is what makes this technique worth paying attention to. A method that works on a browser used by roughly seven in ten people is something that has the potential to affect millions worldwide.
Crucially, this isn’t limited to mobile. The same sign-in-and-sync mechanism works identically on Chrome for Windows and Mac, meaning the technique isn’t confined to phones at all — an abuser only needs brief access to any device the victim uses, on any platform.
Why This Goes Beyond Browsing History
Our research found several features of this technique that make it particularly dangerous, especially in a domestic abuse context:
- There is no warning inside Chrome. Unlike some account-security features on other platforms, there is no pop-up, badge, or notification in the Chrome app to tell a victim that a new account has been signed in or that sync has been switched on.
- Many people don’t realize Chrome is signed in at all. A large proportion of users browse without ever adding an account, so a stalker adding one is a change they’re simply not primed to look for.
- Saved passwords sync too. Once a Google account is added, if the victim ever saves a website password in Chrome, that password becomes visible to the attacker too — turning what looks like a browsing-history issue into a much broader account-takeover risk.
- The victim’s own security alerts don’t fire. Google’s “new sign-in” notifications are tied to the account being signed in — which, in this case, belongs to the attacker.
In a controlling or coercive relationship, the implications are serious. An abusive partner secretly watching which support services, legal resources, or safety websites their victim visits isn’t a hypothetical — it’s precisely the kind of monitoring that domestic abuse support organizations warn is used to maintain control and, in the worst cases, to escalate abuse.
What Could Google Be Doing Better?
Chrome sync itself is a legitimate and useful feature — the issue is the complete absence of any signal when it’s switched on by someone else. Small changes could close that gap without making the feature any less convenient for everyday users:
- A temporary, low-key notification. A brief, dismissible notice — shown for a few days whenever a new account is added or sync is turned on — would be enough to alert an unsuspecting owner without disrupting people who added the account themselves.
- An in-app indicator of sync status. A small, persistent marker showing whether sync is active and which account it’s syncing to would make the current state far easier to notice at a glance.
We’d encourage Google to consider both. Neither would meaningfully affect the experience for the vast majority of users who add accounts themselves — but they could make a real difference for the people this technique is used against.
How to Protect Yourself
The good news is that checking — and fixing — this takes less than a minute, and you don’t need any technical expertise to do it.
➡️ iPhone & iPad:
- Open Chrome.
- Tap the three-dot menu (usually bottom right), then tap Settings.
- At the top of the Settings screen, you’ll see the name or email address of the account currently signed in (or “Sign in to Chrome” if no account is signed in).
- Tap the account name to review it. If you don’t recognize it, tap Manage accounts on this device, then remove or sign out of any account you didn’t add yourself.

Fig 3. Checking the logged in account on iOS.
➡️ Android, PC or Mac:
- Open Chrome.
- Tap your profile icon in the top-right corner (or tap the three-dot menu, then Settings).
- Check the account name shown under “You and Google.” If you don’t recognize it, tap it to review, then choose to sign out or remove it.

Fig 4. Checking the logged in account on Desktop.
If you find an account you don’t recognize, remove it immediately and change passwords for important accounts — especially if you’ve ever saved passwords in Chrome.
Beyond checking your account, a few other habits go a long way:
- Use Incognito mode for sensitive browsing. Pages visited in Incognito aren’t added to your synced history, which is useful if you’re researching something you’d rather keep private.
- Secure your device with a strong passcode. A few unattended minutes is all this technique requires, so a strong PIN, password, or biometric lock is your first line of defense.
- Check for unfamiliar Face ID/Touch ID or fingerprints. An abuser with brief access could also enroll their own biometrics on your device, giving themselves ongoing access even after this issue is fixed.
- Be mindful of who has physical access to your phone. Avoid leaving it unlocked or unattended around anyone you don’t fully trust.
- Trust your instincts. Victims of tech-enabled abuse often describe a sense of “how did they know that?” — if something feels off, it’s worth checking your accounts rather than dismissing the feeling.
The Bottom Line
This technique is a reminder that the biggest privacy risks on your phone aren’t always sophisticated malware — sometimes they’re a legitimate, everyday feature quietly switched on by someone you know. Because it requires no special skill and leaves almost no trace, we expect reports of this kind of abuse to keep growing.
Take two minutes today to check the account signed into Chrome on your devices. It’s a simple step, but for someone in Emma’s position, it could make all the difference.
If you believe you’re being monitored by a partner or ex-partner, you’re not alone, and support is available. Visit our resources page for links to domestic abuse support agencies around the world.