How Google encrypts your saved passwords, where the real risks are and when a dedicated password manager makes more sense.
Is Google Password Manager safe? For most people yes, as long as your Google account is locked down with a passkey or a security key and your computer stays free of malware. Google encrypts every saved password and warns you when one turns up in a known breach. Still, the weak spots sit elsewhere. By default Google holds the encryption key, your Google account works as the master password and malware on your computer can go after what Chrome stores.
A common view among users is that saving passwords with Google beats having no password manager at all. That's true, since reused passwords are the bigger risk. But "safe enough" depends on what you need protection from. Below you'll see how Google encrypts your passwords, which threats it handles, where it falls short and how to close most of the gaps in about 10 minutes.
How safe is Google Password Manager at the storage level? First of all, every password you save is encrypted. The real question is who holds the key. That depends on which of three modes your account is in, so it's worth checking yours.
People often point to AES-256 as proof that it's safe. CHOICE lists AES-256 as Google's encryption claim. In fact, it's a strong cipher. Still, a strong lock doesn't mean much if someone else keeps a copy of the key.
This is the default. Google's help page says the key that decrypts your passwords is stored in your Google Account. Google then uses that key to decrypt your passwords when you need them.
So is Google Password Manager safe with this default? Your passwords are encrypted on Google's servers. Google can still technically decrypt them. That's why reviewers say Google Password Manager doesn't use zero-knowledge encryption, a design where only you hold the key. A PCMag finding cited by Android Police says exactly that.
With on-device encryption turned on, only your devices can decrypt your passwords, after you enter your Google password or your screen lock. Google says no one besides you can access them after that.
There are two catches, though. First, it isn't switched on by default for most people. Also, once it's set up it can't be removed. If you lose your Google password and every device, your passwords go with them. So update your recovery phone number and email before you turn it on. Still, this one setting changes the answer to "is Google Password Manager safe" more than any other.
Passkeys are sign-ins that use your fingerprint, face or screen lock instead of a password. So is Google Password Manager safe for passkeys? Even more so, because Google treats them differently. According to the Google Security Blog, passkeys in Google Password Manager are always encrypted with a key that only your own devices hold, which protects them even from someone inside Google.
To sync passkeys to a new computer, you set a Google Password Manager PIN. It's six digits by default. Otherwise, choose "PIN options" for a longer one. If passkeys are new to you, this guide to how passkeys work explains the basics.
Is it safe to save passwords in Chrome, then? First you need to know where Chrome saves them. The Chrome password manager and Google Password Manager share one screen but not always one storage place. That's why people get confused in forum threads.
Google's Chrome help describes two options. When you're signed in to Chrome, you can save passwords to your Google Account and use them on your other devices. When you're not signed in, Chrome stores them locally on that device only. You can move device-only passwords into your account later.
So one person can end up with some passwords in the cloud, some on a single laptop and a few in both. To check yours, open Chrome, click the three-dot menu and go to Passwords and autofill > Google Password Manager.
The difference matters for safety because each place has a different weak point. Local passwords never reach Google's servers. But they're only as safe as that one computer. Account passwords survive a dead laptop. Still, they're only as safe as your Google account.
Is Google Password Manager safe from hackers? Against attacks on Google itself, mostly yes. Against attacks on your account or your computer, much less so. The table below matches six common threats with what the manager does about each one, so you can see where the gaps are.
Look at the second and fourth rows. In fact, those two cover most real-world password theft. Neither one is about Google's servers.
So is Google Password Manager safe if your PC gets infected? No. But then neither is any other browser password store. Stolen browser passwords usually come from the victim's own device, not from Google. The June 2025 headlines about 16 billion leaked passwords are a good example. Cybernews, whose researchers found the data, said there was no central breach at Google, Apple or Facebook. A Google spokesperson told Axios the same thing. Much of the data came from infostealers, malware that copies saved passwords and cookies from browsers.
On macOS Chrome protects this data with the Keychain, while on Windows it uses the Data Protection API. Google's Chrome security team has said the Windows method doesn't stop malicious apps that run as the logged-in user, which is how infostealers work.
In July 2024 Chrome 127 added App-Bound Encryption on Windows. It ties stored data to Chrome's identity so other apps can't decrypt it. Google started with cookies and said passwords and payment data would follow. It raised the bar, but only for a while. SpyCloud saw infostealers bypassing it less than 45 days after release. A January 2026 analysis by Elcomsoft notes that code injected into Chrome's own process inherits Chrome's trusted identity.
None of this is unique to Google Password Manager security. Any password saved in any browser is at risk when the computer is infected. A dedicated manager with a master password adds one more lock, since its vault stays encrypted until you open it. It still can't save a computer that malware fully controls. That's why the real fix is keeping malware off the machine.
Dedicated password managers win on control. Google, on the other hand, wins on convenience and price. So how secure is Google Password Manager next to the paid options? This table compares the three on the points that affect safety, as of October 2026.
The biggest difference is the master password. With Bitwarden or 1Password, someone who gets into your Google account still can't open your vault. With Google, by contrast, the account is the vault. So is Google Password Manager safe enough to skip a paid manager? For someone who uses one browser and guards the account well, often yes.
Is Google Password Manager safe for everyone? No. It's safe enough for many people and the wrong tool for some. Here's how to tell which group you're in.
Keep using Google Password Manager if:
Consider a dedicated manager if:
If you decide to switch, the order of these steps matters. Google's import and export help page covers the menus.
If you're staying, these steps close most of the gaps from the threat table. After them the answer to "is Google Password Manager safe" gets a lot closer to a plain yes. Do them in this order, since each step builds on the one before.
AI browsers also add a new wrinkle. An AI agent that clicks and fills in forms for you works inside a browser that may already know your passwords.
In August 2025 Brave's security team showed that hidden text on a web page could give instructions to the AI in Perplexity's Comet browser. This is called indirect prompt injection. Perplexity's own security team later called prompt injection an unsolved problem across the industry.
Is Google Password Manager safe to use with an AI agent? Only if you keep control of sign-ins. The practical rule is simple. Let an agent do the research and the routine form filling. Sign in and approve payments yourself. That also applies to every AI browser, Sigma included. For a wider look at the risks, see this piece on AI agent security.
If you'd rather move away from Chrome, Sigma is a free browser built on Chromium. So switching doesn't mean starting over.
Sigma can save passwords itself and import the ones you already have in Chrome. If you want a separate master password, you can install Bitwarden, 1Password or another manager instead, since Sigma runs Chrome extensions.
Sigma also covers the browser side of the threat table. Real-time phishing detection warns you before you type a password into a fake site. Private Profiles keep work, personal and other accounts in separate spaces, with profile data encrypted and secured by a 12-word recovery phrase. The ad blocker and DNS-over-HTTPS are built in. And the AI agent works inside the same browser, so the sign-in rule above applies there too.
Still, Sigma can't clean malware off your computer. No browser can. So keep your system updated whichever browser you choose.
Download Sigma for free on Mac, Windows or iPhone, import your Chrome passwords and see how it fits your routine.
