Google Chrome Secretly Downloads 4 GB AI Model Without User Consent

Original: Google Chrome silently installs a 4 GB AI model on your device without consent

Why This Matters

Major privacy violation affecting billions of Chrome users with significant climate impact

Security researcher Alexander Hanff discovered that Google Chrome automatically downloads a 4 GB Gemini Nano AI model file called 'weights.bin' to users' devices without permission. The file is stored in the OptGuideOnDeviceModel directory and reinstalls itself if deleted. At Chrome's scale of billions of devices, this creates massive environmental impact through CO2 emissions.

Privacy researcher Alexander Hanff found that Chrome silently installs a 4 GB AI model file named 'weights.bin' containing Gemini Nano weights in the OptGuideOnDeviceModel directory. The installation occurs without user consent and the file reinstalls automatically if manually deleted. Hanff estimates the environmental cost at 6,000-60,000 tonnes of CO2-equivalent emissions at Chrome's billion-device scale. He argues this violates EU ePrivacy Directive Article 5(3), GDPR Articles 5(1) and 25, and potentially triggers Corporate Sustainability Reporting Directive obligations. This follows a similar pattern Hanff identified with Anthropic's Claude Desktop installing Native Messaging bridges across multiple browsers without permission.

Source

thatprivacyguy.com — Read original →