Build zero-trust AI agents that judge intent, not just syntax

This blog post explores how to transition AI agents from static, build-time security controls to dynamic runtime governance using the Gemini Enterprise Agent Platform. It highlights three primary managed defenses: Model Armor for screening edge prompts, Semantic Governance Policies for evaluating tool intent against business rules, and Agent Anomaly Detection for catching multi-turn exploits. By shifting these capabilities to the platform level, security administrators can dynamically enforce policies and neutralize complex attacks without needing to modify or redeploy the agent's underlying code.

Chrome for Android Update

    Hi, everyone! We've just released Chrome 153 (153.0.8010.47) for Android. It'll become available on Google Play over the next few days. 

This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.


Android releases contain the same security fixes as their corresponding Desktop releases (Windows & Mac: 153.0.8010.47/.48 Linux: 153.0.8010.47) unless otherwise noted.

Harry Souders

Extended Stable Update for Desktop

 The Extended Stable channel has been updated to 152.0.7977.130 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome

Stable Channel Update for Desktop

The Stable channel has been updated to 153.0.8010.47/.48 for Windows and Mac and 153.0.8010.47 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 42 security fixes. Please see the Chrome Security Page for more information.

[N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03 [TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04 [TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08 [$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25 [$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03 [N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26 [N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26 [N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27 [N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04 [N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08 [N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09 [N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13 [N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13 [N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28 [N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28 [TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14 [TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20 [N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25 [N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26 [N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26 [N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26 [N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26 [N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26 [N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29 [N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02 [TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04 [TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-06 [TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07 [TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07 [N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08 [TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@lbherrera_) on 2026-01-07 [TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08 [N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16 [N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29 [N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29 [N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09 [N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14 [N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19 [TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07 [TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31 [TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@nmzabith) on 2026-08-03

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

Connect to Google Meet hardware with room codes now generally available

Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Building on the recent Connect Room launch that uses proximity-based detection to identify nearby hardware, this update provides a reliable manual fallback when ultrasound is unavailable or disabled. Users will see a "Connect with room code" button on their device’s pre-call screen, which allows them to enter the alphanumeric code displayed directly on the hardware’s screen.

See our Early Preview announcement for full details.


Getting started

  • Admins: This feature will be ON by default and can be disabled/enabled at the device level. We have updated our admin settings for Connect room and related features, visit the Help Center to learn more.
  • End users: This feature will be ON by default. Your admin can turn this feature off for devices in your organization.

Rollout pace

Availability

  • Available to all Google Workspace customers with Google Meet hardware devices

Resources



Connect to more tools with Gemini in Google Workspace

Users will now be able to use Gemini in Workspace to directly interact with Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit Quickbooks, Monday, and Salesforce through Model Context Protocol (MCP) integrations. This will enable them to access information directly without needing to switch tabs, download files, or interrupt workflows across our Google Workspace apps including Sheets, Gmail, Drive, Docs, Chat, and more.

Getting started

  • Admins: This feature will be ON by default for users with Gemini for Google Workspace access, and can be managed at the domain, organizational unit (OU), or group level in the Admin console under Apps > Google Workspace > Gemini for Workspace > Third-Party Connectors. Admins can control which third-party connectors are enabled for their organization and manage access policies. Visit the Help Center to learn more about managing third-party connectors for Gemini.
  • End users: Once enabled by an admin, end users can access third-party connectors through the Gemini side panel in Docs, Sheets, and Slides, as well as in Google Chat. Visit the Help Center to learn more about third party integrations with Gemini in Google Workspace.

Rollout pace

Availability

  • Business: Business, Standard, and Plus
  • Enterprise: Enterprise, Standard, and Plus
  • Consumer: Google AI , Pro, and Ultra
  • Other Editions: Enterprise Essentials Plus
  • Education Add-ons: Google AI Pro for Education; Teaching and Learning; Endpoint Education

Resources



gFiber: Consumers’ Favorite Internet

Thumbnail
In 2023, 2024, and 2025 gFiber was awarded #1 in Customer Satisfaction for Residential Wired Internet Service in the South Region by J.D. Power. J.D. Power has been delivering incisive industry intelligence on customer interactions with brands and products for more than 55 years. For gFiber, this award is a reflection of its commitment to customers. 

With the majority of its customers living in the states that comprise J.D. Powers’ south category (shown in green below), gFiber qualified for inclusion in that region. While not having enough surveys to qualify for consideration in other regions, gFiber’s score actually topped providers across all regions where gFiber operates.

J.D. Power regional map

What J.D. Power measures

The J.D. Power study amplifies the voice of the customer by analyzing feedback from over 27,000 residential internet users. For the 2025 study, satisfaction was measured across seven facets of service. gFiber ranked #1 in the South in all of those categories:

  1. Consistently delivering high-quality service

  2. Problem resolution

  3. Ease of doing business 

  4. App & website satisfaction 

  5. Value for price paid

  6. Most trusted provider

  7. Staff 

This marks the third year in a row that gFiber not only earned the top spot for internet satisfaction overall but also swept every single sub-factor in the award.

gFiber scored the highest Overall Satisfaction among all providers surveyed in 2025. In fact, gFiber ranked #1 in all seven of the sub categories measured. Those scores reflect choices gFiber has made since the beginning to deliver internet people can actually love. 


Why customers choose gFiber

From its start in 2012, gFiber designed its internet service to be technologically the most advanced, but also straightforward, consistent, and transparent—so you never have to worry about the pricing games or service issues so often seen in this industry. gFiber offers flat, all-in pricing, with monthly internet rates that have remained the same since they launched. There are no gimmicks, no contracts, no data limits, and no equipment rental fees. You don’t have to get tripped up by the "fine print" of a promotional trap to get the best service available. Instead you get an experience that consumers describe as “brilliant.” 


gFiber offers symmetrical speed, which means your upload and download speeds are equally fast. Core 1 Gig is 1000 Mbps for uploads and downloads. The same symmetrical connectivity applies to Home 3 Gig, Edge 8 gig, and even 20 gig service in testing. Our 100% fiber-optic technology is built to handle everything from 8K streaming to remote work without breaking your flow. 


gFiber has been applauded for speed, reliability, customer satisfaction, and being the best overall home internet service. Independent industry experts consistently rate gFiber as the gold standard year after year.


The awards are not just limited to the J.D. Power awards either. Recent gFiber accolades include:


  • Forbes Home: 3x Winner Forbes Home Best Fiber Internet 2024, 2025 & 2026 

  • HighSpeedInternet.com: 2x Winner HighspeedInternet.com Best Overall for 2025 and 2024

  • Highspeedinternet.com Best Customer Service for 2025 

  • Reviews.org: 2x Winner Reviews.org Best Overall 2025 & 2026 

  • PCMag: 5x Winner PCMag Readers' Choice Best Overall ISP 

  • CNET: Best Fiber Internet of 2025 & 2026 (National) - Best Provider for gig and multigig

gFiber is honored by the industry recognition, but is even more grateful for the trust our customers place in us every day. 

Available service

To check availability in your area visit gfiber.com, and enter your address. 



Footnotes

J.D. Power Disclaimer: gFiber (formerly Google Fiber) received the highest score in the South region of the J.D. Power 2023-2025 U.S. Residential Internet Service Provider Satisfaction Studies, which measures customers’ satisfaction of service with their current internet provider. Visit jdpower.com/awards for more details.

Forbes Home: Awarded Best Fiber Internet: Best Internet Providers Of 2026, Forbes Home.

HighSpeedInternet.com Named 2025’s Best Overall Internet Provider in the U.S. according to HighSpeedInternet.com. 

CNET and PCMag: A trademark of Ziff Davis, LLC. Used under license; Reprinted with permission. © 2025 Ziff Davis, LLC. All Rights Reserved.

Gmail Search’s AI Overviews now available globally

We recently announced the launch of AI Overviews in Gmail search which allows users to ask natural language questions in Gmail’s search bar and get concise summaries and answers without digging through emails. Starting today, we are expanding access to AI Overviews in Gmail search to global users (with paid plans) who have their Gmail language set as English. Previously, this was only available to users in the US with their language set as English.

Getting started

Rollout pace

  • Rapid Release domains: Gradual rollout (up to 15 days for feature visibility) started on September 3, 2026 
  • Scheduled Release domains: Full rollout (1–3 days for feature visibility) starting on September 21, 2026
  • Personal Google Accounts (Consumer): Gradual rollout started on September 3, 2026

Availability

  • Business: Business Starter, Standard, and Plus
  • Enterprise: Enterprise Starter, Standard, and Plus
  • Consumers: Google AI Plus, Pro, and Ultra (excluding personal accounts in the EEA, UK, Switzerland, and Japan)
  • Other Editions: Frontline Plus
  • Education Add-ons: Google AI Pro for Education
  • Other Add-ons: AI Expanded Access

Resources