Sunday, May 18, 2025
HomeAIChrome 137 Integrates Gemini Nano AI to Combat Tech Support Scams

Chrome 137 Integrates Gemini Nano AI to Combat Tech Support Scams

Published on

SIEM as a Service

Follow Us on Google News

Google has unveiled a groundbreaking defense mechanism in Chrome 137, integrating its on-device Gemini Nano large language model (LLM) to detect and block these malicious campaigns in real time.

This update marks a significant leap in combating evolving cyber threats by leveraging artificial intelligence directly within users’ browsers.

Tech support scams exploit psychological manipulation, mimicking legitimate security alerts to trick users into believing their devices are compromised.

- Advertisement - Google News

Attackers frequently use aggressive tactics like locking keyboard inputs or displaying counterfeit system scans to pressure victims into paying for unnecessary services.

According to Google’s internal data, the average malicious site exists for fewer than 10 minutes, making traditional blocklist-based defenses less effective against ephemeral threats. This evasion strategy has necessitated a more dynamic approach to cybersecurity.

Gemini Nano Enhances Chrome’s Defenses

Chrome 137 introduces on-device AI analysis through Gemini Nano, a lightweight LLM that evaluates webpage content in real time.

When users navigate to a site, Chrome detects triggers associated with scams-such as the misuse of keyboard-lock APIs-and activates Gemini Nano to analyze the page’s intent.

The model processes text, layout, and behavioral cues to identify deceptive patterns, generating security signals for Google’s Safe Browsing service.

The on-device execution ensures privacy and immediacy. By processing data locally, Chrome avoids transmitting sensitive information to external servers, aligning with growing demands for user-centric privacy.

Additionally, this approach allows Chrome to analyze pages as users see them, circumventing rendering tricks used to evade cloud-based crawlers.

When a user navigates to a potentially dangerous page, specific triggers that are characteristic of tech support scams (for example, the use of the keyboard lock API) will cause Chrome to evaluate the page using the on-device Gemini Nano LLM.

Chrome provides the LLM with the contents of the page that the user is on and queries it to extract security signals, such as the intent of the page.

Performance and Privacy

Google emphasizes that Gemini Nano operates efficiently without degrading browser performance.

The LLM runs asynchronously, prioritizing user tasks, and employs throttling mechanisms to limit GPU usage.

Crucially, summarized security signals are only sent to Safe Browsing for users enrolled in Enhanced Protection mode, which proactively blocks unknown threats.

Standard Protection users benefit indirectly as newly identified scams are added to blocklists.

Google plans to extend Gemini Nano’s capabilities to combat other scam types, such as fake package tracking and unpaid toll notices, which have surged in recent years.

The company is also exploring Android integration for mobile users and refining defenses against adversarial tactics like prompt injection attacks, where scammers attempt to confuse AI models with hidden text.

Chrome 137’s AI-driven defense system represents a paradigm shift in cybersecurity.

By harnessing on-device LLMs, Google not only addresses the limitations of traditional blocklists but also sets a precedent for real-time, adaptive threat detection.

As scammers grow more sophisticated, such innovations underscore the critical role of AI in safeguarding digital ecosystems-without compromising user privacy or performance.

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Kaaviya
Kaaviya
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Latest articles

VMware ESXi, Firefox, Red Hat Linux & SharePoint Hacked – Pwn2Own Day 2

Security researchers demonstrated their prowess on the second day of Pwn2Own Berlin 2025, discovering...

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...

New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads

A newly identified ransomware campaign has emerged, seemingly targeting supporters of Elon Musk through...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

VMware ESXi, Firefox, Red Hat Linux & SharePoint Hacked – Pwn2Own Day 2

Security researchers demonstrated their prowess on the second day of Pwn2Own Berlin 2025, discovering...

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...