This fake Google Security check can steal your passwords. Here’s how to stay safe
A new phishing campaign is impersonating Google’s account security checks to trick users into installing a malicious web app that steals passwords, passcodes, and other sensitive data directly from the browser. The post This fake Google Security check can...
A fake Google security page installs malicious web app to steal passwords and authentication codes
Manisha Priyadarshini / Digital Trends
A new phishing campaign is using a fake Google security check to steal passwords and other sensitive data from unsuspecting users.
Researchers at Malwarebytes warn that the scam impersonates Google’s account protection system, tricking victims into installing a malicious web app.
Once installed, the tool quietly collects credentials, one-time passcodes, and other personal information. The scam begins with a fake Google account security page designed to look authentic.
Fake Google Security check Malwarebytes
Victims are asked to complete a security verification step to protect their account. Instead of protecting their account, the process installs a rogue Progressive Web App (PWA), often through a domain designed to look legitimate, such as google-prism[.]com.
How the fake Google security page steals your data
Progressive Web Apps are normally used to make websites behave like installed applications. In this case, attackers abuse it to deploy a malicious app directly through the browser.
Malwarebytes
After installation, the PWA seeks permission to send notifications and access clipboard data and other browser functions, then deploys a service worker that enables push alerts, background operations, and sensitive data collection.
Researchers say it can steal login credentials, intercept OTPs used for multi-factor authentication, and harvest cryptocurrency wallet addresses. The tool may also access clipboard data, collect GPS location information, and capture other device details.
The attack can also turn a victim’s browser into a proxy that routes traffic for the attackers. This means cybercriminals can hide their activity behind the user’s device while continuing to monitor data from the compromised browser.
Malwarebytes
This incident highlights a broader trend in cybercrime, where even modern AI tools can be abused, with researchers showing that browsing-enabled chatbots can act as stealthy relays for malware traffic.
How to stay protected?
Google does not run security checks through random pop-up pages. If a “security alert” asks you to install software, enable notifications, or share contacts, close it. Real security tools are available only through your account at myaccount.google.com.
Staying safe requires paying close attention to security prompts and website addresses. You should always check the URL before entering login details and avoid installing unknown web apps.
Enabling two-factor authentication and using a password manager can also add extra protection if credentials are exposed.
Google is also stepping up defenses against emerging threats. The company recently flagged a new AI-powered malware that can rewrite its own code in real time.
This is why Chrome is testing Gemini-based anti-scam protection to automatically flag suspicious websites before users fall for phishing attacks.

Manisha likes to cover technology that is a part of everyday life, from smartphones & apps to gaming & streaming…
Apple’s upcoming low-cost laptop could be the MacBook Neo
Accidental slip-up reveals MacBook Neo as Apple's new budget laptop.
Apple may be gearing up to introduce a lower-cost MacBook as early as this week, and according to an accidental mention on Apple's own support site, it could be called the MacBook Neo. The name briefly made an appearance in a support document URL, which has now been removed.
MacBook Neo might be the new entry-level Apple laptop
Apple reveals M5 Pro and M5 Max silicon with an all-big-core design and big performance gains

Apple has introduced its newest professional silicon, the M5 Pro and M5 Max, marking a significant leap in performance for its high-end Macs. Built on an all-big-core design that focuses on raw compute power and efficient execution of demanding workflows, these chips are aimed squarely at creative professionals, developers, and anyone whose work pushes traditional laptop performance limits.
The announcement signals a continued evolution of Apple’s silicon strategy, one that started with the first generation of M-series chips and has steadily expanded into more capable, specialised processors. With the M5 Pro and M5 Max, Apple has moved beyond incremental improvements and delivered substantial performance gains that pose a serious challenge to conventional workstation CPUs.
Apple’s new Studio Display XDR shrinks Pro XDR into a brighter, more affordable miniLED monitor
Studio Display XDR takes over from Pro Display XDR with a smaller but brighter miniLED display.

Apple is ending the Pro Display XDR era with a brand-new professional-grade monitor called the Studio Display XDR. It arrives as a new flagship standalone monitor that takes premium display technology and places it into a smaller, brighter, and relatively more affordable package.
The Studio Display XDR inherits many of the advanced features creators love from the last-gen model, while improving brightness and adaptability for improved creative and professional workflows.
BigThink