securitylab_n•July 16, 2026•🇷🇺Translated from Russian

69% of Browsers Worldwide Vulnerable: How Chrome Sync Enables Stealth Surveillance Without Malware

Google Chrome’s ordinary sync feature can be covertly exploited to transform the browser into a powerful surveillance instrument. Attackers require neither malware nor advanced technical skills—only a few minutes of physical access to the target device to sign in with their own Google account and enable synchronization.

Specialists at Certo identified the technique after investigating multiple reports of digital stalking by intimate partners. In one documented case, a woman researching family lawyers and visiting websites that assist victims of domestic abuse discovered that her partner was able to recount the exact pages she had opened and the precise times she had visited them—despite her using only her personal phone and noticing no new applications.

The partner had briefly obtained the device, opened Chrome, signed in under his own Google credentials, and activated sync. From that moment, the victim’s browsing history began automatically uploading to his profile, which he could access from any other phone or computer anywhere in the world. No password belonging to the victim was needed, and login notifications were delivered exclusively to the attacker’s account rather than the device owner.

The risk extends far beyond visited websites. Chrome can also synchronize bookmarks, open tabs, autofill information, and stored passwords. If a victim later saves credentials for any service while the attacker’s profile remains active, those passwords become visible to the attacker, potentially enabling further account takeovers.

Chrome displays no prominent alert when a new profile is added or when synchronization begins. Many users never inspect which Google account is currently linked to the browser. According to StatCounter, Chrome commanded 69.65% of the global browser market in June 2026, meaning the simple attack vector could affect millions of people. The same method functions on smartphones as well as on Windows and macOS computers.

Certo has urged Google to introduce temporary notifications whenever a new account is connected and to display the currently synced profile persistently. Such measures would allow device owners to detect unauthorized access quickly without disrupting normal browser operation.

Users can verify the connected profile through browser settings. On iPhone and iPad, the account address appears at the top of the settings section. On Android, Windows, and macOS, it is visible after clicking the profile icon. Any unfamiliar account should be removed immediately, and passwords for important services—especially those saved in Chrome—should be changed.

For sensitive searches, the Incognito mode can be used, as visited pages are not added to the synchronized history. Devices should be protected with strong passcodes and biometric authentication, and users should review whether additional fingerprints or facial-recognition data have been enrolled by third parties.

Related articles

Habr•Privacy & Surveillance

GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use

This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.

Habr•Privacy & Surveillance

Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection

A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.

AntiMalware•Privacy & Surveillance

WhatsApp Introduces Parental Controls for Teen Privacy Settings

WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.

Securitylab•Privacy & Surveillance

Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained

A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.