Chrome Gemini Password Change Feature Tested in Canary Build
Chrome Canary is testing a Gemini-powered option that would replace weak or reused passwords automatically instead of just flagging them. It does not work yet. In hands-on testing on Windows 11, clicking the new "Change it for me" button left Chrome's password manager stuck on "Attempting to sign-in..." before it threw an error saying the password could not be updated, Android Authority reported this week after confirming the feature in its own build.
The Chrome Gemini password change feature lives behind a hidden flag called "Password change with Glic," and it is currently limited to desktop builds of Chrome Canary. Browser tipster Leopeva64 spotted it first, on X, before Android Authority tested it directly and hit the same failure. The flag is not available yet in Chrome Canary for Android, Android Authority reports.
What the Chrome Change it for me password option actually does
Enable the flag, and the layout of Chrome's Password Manager changes. The standard "Change password" link, which normally sends users to a site's own account settings, gets replaced by a "Change it for me" button carrying Gemini's sparkle icon, Android Authority found in its own Canary testing.
The goal, as Google appears to have designed it, is to skip the manual detour entirely. Rather than making users hunt down a site's settings page and reset credentials by hand, Google wants Gemini to handle the reset process on its own, according to Android Authority.
This isn't a new idea so much as an old one resurfacing. Early traces of AI password tools turned up in Chrome's Gerrit code commits back in 2024, Android Authority notes, which points to a longer-running project rather than a rushed release.
It also builds on something Chrome already does. The browser can automatically change passwords on supported sites once it detects they've been compromised in a known breach, Android Authority reports. The Canary experiment appears to extend that same automation to passwords that are merely weak or reused, Android Authority notes, a much larger category of accounts if it ships.
Chrome Canary Password change with Glic flag: why it fails in testing
The button exists, but the tested build did not complete the job. Clicking "Change it for me" got as far as attempting sign-in before erroring out, per Android Authority's account of its own Windows 11 test.
Google's own documentation offers a clue as to why the feature might still be shaky. Gemini's broader "auto browse" capability, which can complete multistep web tasks and, with permission, tap Google Password Manager to sign into sites, is still being rolled out gradually and remains unavailable in Live chats or on iPhone, according to Google's support page. In early 2025, Android Police reported that Google's plans for automated password replacement were still in development and that Google had not detailed how the process would ultimately work, the outlet noted, a description that still seems to fit what showed up in Canary a year and a half later.
That uncertainty lines up with a familiar problem in browser automation. Scripts built to click through websites on a user's behalf tend to struggle with custom two-factor prompts and login forms that don't follow standard patterns, Android Authority notes, and a password-reset flow is about as likely as any task to run into exactly that kind of friction.
Why the reuse problem makes the experiment worth watching
The appeal of a Gemini auto-fix for passwords in Chrome comes down to a habit most people never break. Americans reuse the same password across at least four accounts on average, according to a Forbes Advisor study cited by Android Police, and reused credentials accounted for roughly 30% of compromised passwords in 2024 despite reuse being a well-documented risk, per the same report.
Federal guidance has already shifted toward assuming people lean on password managers rather than memorize a unique string for every account. NIST's SP 800-63B-4, the federal digital identity standard finalized in September 2024, calls for allowing pasting into password fields specifically to support manager use, bars forced periodic password rotation unless there's evidence of compromise, and calls for screening new passwords against breach databases, according to a summary of the standard. The same guidance places phishing-resistant methods like FIDO2 and WebAuthn above password-plus-MFA combinations in its authentication hierarchy, the summary notes.
Against that policy shift, immediately replacing a compromised or weak password is a step many people skip even after a breach makes the risk obvious, Android Police points out. That gap is the strongest case for a Chrome AI password manager feature along these lines. It doesn't, on its own, explain why this particular build shipped before it could finish a single reset.
Can Gemini be trusted with a task this sensitive
Google's own documentation is candid about the tradeoffs of letting an AI agent act on a user's behalf. Password Manager does not share stored passwords with Gemini, but users remain responsible for whatever Gemini does during a task, mistakes included, Google's support page states. Google also warns that Gemini may misread what a user wants or misjudge the site it is browsing, and that it may share user information with that site while completing a task, according to the same documentation.
Chrome does build in some guardrails, including prompts asking users to confirm certain actions before Gemini proceeds. But Google frames something more basic, actively watching what the agent is doing, as "the most important" defense against it going wrong, per its support documentation. That's a notable admission for a feature whose entire pitch is hands-off automation.
Android Police raises a separate objection: even a flawless automated reset might not move the needle on account security. If the feature simply reassures people that Gemini has already handled their weak passwords, it could ease the vigilance that actually prevents compromises, the outlet argues, without touching the reuse habits that caused the exposure in the first place.
What Google still has to answer
Right now, this is a hidden flag whose password-change flow failed in Android Authority's test, with no confirmed timeline and no Android build yet, per Android Authority. Getting from that point to a reliable Gemini weak and reused password replacement tool means answering questions the current build doesn't.
Among them: how the flow handles sites with two-factor authentication and nonstandard login forms, which confirmation steps Gemini will require before it submits a new password, what happens to account access if a reset fails partway through, and how the replacement password gets stored and retrieved afterward. None of that is addressed in what's shipped so far.
The broader policy direction, meanwhile, already points past passwords altogether. NIST ranks phishing-resistant authenticators above password-plus-MFA, according to the standard's summary, which suggests the more durable fix is passkeys rather than a faster way to generate new passwords. For now, the button sits behind a flag on desktop Canary, and it does not complete the password change in the test Android Authority described.
Comments
Be the first, drop a comment!