Is Google Password Manager safe? The real risks explained

How Google encrypts your saved passwords, where the real risks are and when a dedicated password manager makes more sense.

Table of contents

Is Google Password Manager safe? For most people yes, as long as your Google account is locked down with a passkey or a security key and your computer stays free of malware. Google encrypts every saved password and warns you when one turns up in a known breach. Still, the weak spots sit elsewhere. By default Google holds the encryption key, your Google account works as the master password and malware on your computer can go after what Chrome stores.

A common view among users is that saving passwords with Google beats having no password manager at all. That's true, since reused passwords are the bigger risk. But "safe enough" depends on what you need protection from. Below you'll see how Google encrypts your passwords, which threats it handles, where it falls short and how to close most of the gaps in about 10 minutes.

Google Password Manager at a glance
WHAT IT HANDLES WELL
  • Encrypting saved passwords on Google's servers and in sync
  • Warning you when a saved password shows up in a known breach
  • Offering a password only on the site it was saved for
  • Keeping passkeys encrypted with a key Google doesn't have
WHERE IT FALLS SHORT
  • Google holds the key to your passwords unless you turn on on-device encryption
  • Your Google account works as the master password
  • Malware on your computer can go after what Chrome stores
  • It works best inside Chrome and on Android only
Settings fix the first two weak spots. The third one depends on keeping your computer clean.

How Google Password Manager encrypts your passwords

How safe is Google Password Manager at the storage level? First of all, every password you save is encrypted. The real question is who holds the key. That depends on which of three modes your account is in, so it's worth checking yours.

People often point to AES-256 as proof that it's safe. CHOICE lists AES-256 as Google's encryption claim. In fact, it's a strong cipher. Still, a strong lock doesn't mean much if someone else keeps a copy of the key.

Standard encryption keeps the key in your Google Account

This is the default. Google's help page says the key that decrypts your passwords is stored in your Google Account. Google then uses that key to decrypt your passwords when you need them.

So is Google Password Manager safe with this default? Your passwords are encrypted on Google's servers. Google can still technically decrypt them. That's why reviewers say Google Password Manager doesn't use zero-knowledge encryption, a design where only you hold the key. A PCMag finding cited by Android Police says exactly that.

On-device encryption moves the key to your devices

With on-device encryption turned on, only your devices can decrypt your passwords, after you enter your Google password or your screen lock. Google says no one besides you can access them after that.

There are two catches, though. First, it isn't switched on by default for most people. Also, once it's set up it can't be removed. If you lose your Google password and every device, your passwords go with them. So update your recovery phone number and email before you turn it on. Still, this one setting changes the answer to "is Google Password Manager safe" more than any other.

Passkeys get the strongest protection

Passkeys are sign-ins that use your fingerprint, face or screen lock instead of a password. So is Google Password Manager safe for passkeys? Even more so, because Google treats them differently. According to the Google Security Blog, passkeys in Google Password Manager are always encrypted with a key that only your own devices hold, which protects them even from someone inside Google.

To sync passkeys to a new computer, you set a Google Password Manager PIN. It's six digits by default. Otherwise, choose "PIN options" for a longer one. If passkeys are new to you, this guide to how passkeys work explains the basics.

Who holds the key to your passwords
DEFAULT
Standard encryption
Key stored inYour Google Account
Can Google decrypt it?Yes, technically
How you get itNothing to do
OPT-IN
On-device encryption
Key stored inYour devices
Can Google decrypt it?No, per Google
How you get itSettings, can't be undone
ALWAYS ON
Passkeys
Key stored inYour devices
Can Google decrypt it?No, per Google
How you get itPassword Manager PIN to sync
Sources: Google Account Help (on-device encryption), Google Security Blog (passkeys, 2022), Google blog (Password Manager PIN, September 2024).

Chrome passwords and Google Password Manager aren't always the same place

Is it safe to save passwords in Chrome, then? First you need to know where Chrome saves them. The Chrome password manager and Google Password Manager share one screen but not always one storage place. That's why people get confused in forum threads.

Google's Chrome help describes two options. When you're signed in to Chrome, you can save passwords to your Google Account and use them on your other devices. When you're not signed in, Chrome stores them locally on that device only. You can move device-only passwords into your account later.

Where Chrome keeps your passwords
SAVED TO THIS DEVICE
Chrome while signed out
StoredOnly on this computer
Reaches Google's serversNo
Survives a lost laptopNo
Main riskMalware on that computer
SAVED TO GOOGLE ACCOUNT
Chrome while signed in
StoredYour Google Account, synced
Reaches Google's serversYes, encrypted
Survives a lost laptopYes
Main riskSomeone taking over your account
Both lists appear in the same Google Password Manager screen. You can move device-only passwords into your account at any time.

So one person can end up with some passwords in the cloud, some on a single laptop and a few in both. To check yours, open Chrome, click the three-dot menu and go to Passwords and autofill > Google Password Manager.

The difference matters for safety because each place has a different weak point. Local passwords never reach Google's servers. But they're only as safe as that one computer. Account passwords survive a dead laptop. Still, they're only as safe as your Google account.

Six threats and how Google Password Manager handles them

Is Google Password Manager safe from hackers? Against attacks on Google itself, mostly yes. Against attacks on your account or your computer, much less so. The table below matches six common threats with what the manager does about each one, so you can see where the gaps are.

ThreatDoes Google Password Manager protect you?What you can do
Someone breaks into Google's serversMostly. Passwords are stored encrypted. With on-device encryption Google says it can't decrypt them either.Turn on on-device encryption
Someone takes over your Google accountNot much. The account works as your master password. A signed-in attacker can reach passwords saved with standard encryption.Use a passkey or security key on the account, not SMS codes
A fake login page that looks like your bankPartly. Saved passwords are offered only on the site they belong to, so a lookalike page gets no autofill. You can still type the password in by hand.Treat a missing autofill as a warning sign
Infostealer malware on your computerNot much. Malware running as you can go after what Chrome stores, and stealers have bypassed Chrome's newer protections.Keep your system updated, skip cracked software, use antivirus
Someone picks up your unlocked laptop or phonePartly. Chrome asks for your screen lock before it shows or exports a password. Autofill and open accounts may still work.Short auto-lock, and require the screen lock for autofill
Google itselfDepends on the mode. With standard encryption Google holds the key. On-device encryption and passkeys take it away.Turn on on-device encryption

Look at the second and fourth rows. In fact, those two cover most real-world password theft. Neither one is about Google's servers.

The real weak spot is malware on your computer

So is Google Password Manager safe if your PC gets infected? No. But then neither is any other browser password store. Stolen browser passwords usually come from the victim's own device, not from Google. The June 2025 headlines about 16 billion leaked passwords are a good example. Cybernews, whose researchers found the data, said there was no central breach at Google, Apple or Facebook. A Google spokesperson told Axios the same thing. Much of the data came from infostealers, malware that copies saved passwords and cookies from browsers.

On macOS Chrome protects this data with the Keychain, while on Windows it uses the Data Protection API. Google's Chrome security team has said the Windows method doesn't stop malicious apps that run as the logged-in user, which is how infostealers work.

In July 2024 Chrome 127 added App-Bound Encryption on Windows. It ties stored data to Chrome's identity so other apps can't decrypt it. Google started with cookies and said passwords and payment data would follow. It raised the bar, but only for a while. SpyCloud saw infostealers bypassing it less than 45 days after release. A January 2026 analysis by Elcomsoft notes that code injected into Chrome's own process inherits Chrome's trusted identity.

How long Chrome's new protection held up
July 30, 2024
App-Bound Encryption ships
Chrome 127 on Windows ties stored cookies to Chrome's identity. Passwords are planned next.
September 12, 2024
First bypasses seen
SpyCloud spots infostealers getting around it, less than 45 days after release.
November 2024
Several methods in the wild
Red Canary documents stealers that switch the protection off through a Chrome policy setting.
January 2026
Still a cat and mouse game
Elcomsoft notes that code injected into Chrome's own process inherits its trusted identity.
Sources: Google Security Blog, SpyCloud, Red Canary, Elcomsoft. The takeaway: once malware runs on your computer, browser encryption slows it down but rarely stops it.

None of this is unique to Google Password Manager security. Any password saved in any browser is at risk when the computer is infected. A dedicated manager with a master password adds one more lock, since its vault stays encrypted until you open it. It still can't save a computer that malware fully controls. That's why the real fix is keeping malware off the machine.

Google Password Manager vs Bitwarden and 1Password

Dedicated password managers win on control. Google, on the other hand, wins on convenience and price. So how secure is Google Password Manager next to the paid options? This table compares the three on the points that affect safety, as of October 2026.

Google Password ManagerBitwarden1Password
Price (Oct 2026)FreeFree plan. Premium $19.80 a yearNo free plan. Individual $47.88 a year
Who can decrypt your vault by defaultGoogle, unless you turn on on-device encryptionOnly youOnly you (master password plus Secret Key)
Separate master passwordNo, your Google account is the keyYesYes
Where it worksBest in Chrome and on Android. Other browsers only through passwords.google.comApps and extensions for major browsers and systemsApps and extensions for major browsers and systems
History of old passwordsNot offeredYesYes

Prices: Bitwarden announcement via Thurrott, 1Password renewal pricing from March 27, 2026 via TidBITS.

The biggest difference is the master password. With Bitwarden or 1Password, someone who gets into your Google account still can't open your vault. With Google, by contrast, the account is the vault. So is Google Password Manager safe enough to skip a paid manager? For someone who uses one browser and guards the account well, often yes.

Is Google Password Manager safe enough for you?

Is Google Password Manager safe for everyone? No. It's safe enough for many people and the wrong tool for some. Here's how to tell which group you're in.

Keep using Google Password Manager if:

  • You use Chrome on all your devices and don't want another app to manage.
  • Your Google account is protected by a passkey or a security key and has current recovery options.
  • You're willing to turn on on-device encryption.
  • Your realistic alternative is reusing the same few passwords. Even then, any password manager beats that.

Consider a dedicated manager if:

  • You switch between browsers or share a computer with other people.
  • Losing your Google account would also lock you out of everything else.
  • You want a separate master password and a history of old passwords. Some users report Google saving a one-time code over a real password, with no way to undo it.
  • You manage logins for work or for clients.

How to move your passwords out safely

If you decide to switch, the order of these steps matters. Google's import and export help page covers the menus.

  1. In Chrome open Google Password Manager > Settings and click Download file next to Export passwords. Chrome then saves an unencrypted CSV file.
  2. Import that file into your new password manager or browser. Most of them accept Chrome's CSV format, so this step is quick.
  3. Delete the CSV file right away and empty the trash. Google warns that anyone who uses the device can open it otherwise.
  4. Passkeys don't come along in the CSV. Make sure you can still sign in to every account that uses a passkey saved in Google.
  5. Only then remove your data with Settings > Delete all Google Password Manager data. This is permanent, so don't rush it.
  6. Turn off "Offer to save passwords and passkeys" so Chrome stops saving new ones.

Make Google Password Manager safer in 10 minutes

If you're staying, these steps close most of the gaps from the threat table. After them the answer to "is Google Password Manager safe" gets a lot closer to a plain yes. Do them in this order, since each step builds on the one before.

  1. Protect your Google account first. Add a passkey or a hardware security key and drop SMS codes as your main second step. Careful users often keep two security keys, one stored as a backup. That's a sound setup, because losing one key won't lock you out.
  2. Update your recovery phone and email. You'll need them before the next step.
  3. Turn on on-device encryption. In Chrome open Google Password Manager > Settings. On the web go to passwords.google.com and open Settings. Remember that it can't be turned off later.
  4. Run Password Checkup. It flags saved passwords that are compromised, reused or weak. Then change the compromised ones before anything else.
  5. Switch on Enhanced protection. In Chrome go to Settings > Privacy and security > Security.
  6. Require your screen lock for autofill. On computers that support it, Google Password Manager settings let you confirm with your device password or fingerprint before Chrome fills a password.
  7. Remove old devices. Check myaccount.google.com > Security > Your devices and sign out of anything you don't recognize.
  8. Keep Chrome and your OS updated. And skip cracked software, which is a common way infostealers get in.

Before an AI agent signs in for you, check what it's doing

AI browsers also add a new wrinkle. An AI agent that clicks and fills in forms for you works inside a browser that may already know your passwords.

In August 2025 Brave's security team showed that hidden text on a web page could give instructions to the AI in Perplexity's Comet browser. This is called indirect prompt injection. Perplexity's own security team later called prompt injection an unsolved problem across the industry.

Is Google Password Manager safe to use with an AI agent? Only if you keep control of sign-ins. The practical rule is simple. Let an agent do the research and the routine form filling. Sign in and approve payments yourself. That also applies to every AI browser, Sigma included. For a wider look at the risks, see this piece on AI agent security.

A safer password setup in Sigma

If you'd rather move away from Chrome, Sigma is a free browser built on Chromium. So switching doesn't mean starting over.

Sigma can save passwords itself and import the ones you already have in Chrome. If you want a separate master password, you can install Bitwarden, 1Password or another manager instead, since Sigma runs Chrome extensions.

Sigma also covers the browser side of the threat table. Real-time phishing detection warns you before you type a password into a fake site. Private Profiles keep work, personal and other accounts in separate spaces, with profile data encrypted and secured by a 12-word recovery phrase. The ad blocker and DNS-over-HTTPS are built in. And the AI agent works inside the same browser, so the sign-in rule above applies there too.

Still, Sigma can't clean malware off your computer. No browser can. So keep your system updated whichever browser you choose.

Download Sigma for free on Mac, Windows or iPhone, import your Chrome passwords and see how it fits your routine.

Switch from Chrome without losing a single password
Sigma imports your saved passwords and warns you before you type one into a phishing page. Free on Mac, Windows and iPhone.
Download Sigma

Download Sigma Browser

Also available on Windows, iOS and Android. Linux version coming soon!

Questions & Answers

If you have any questions,
reach out to us on X at @Sigma_Browser
Can Google see my saved passwords?
Can Google Password Manager be hacked?
Are Google passkeys safe?
Is Chrome's saved password list the same as Google Password Manager?
Does Google warn you if a saved password leaks?
×

Get Sigma on Android

We’ll let you know when Sigma for Android launches.
You’re on the list!
Please enter a valid email address.
Oops! Something went wrong while submitting the form.
Oops! Something went wrong while submitting the form.