Google bans embedded in-app sign-ins to curb phishing attacks

Embedded browsers leave Google’s users susceptible to phishing attacks from bad actors.
Google bans embedded in-app sign-ins to curb phishing attacks
Google will soon block in-app embedded browser logins to fight against phishing attacks. Credit: Thomas Trutschel/Photothek via Getty Images

Google is taking a big step to fight phishing attempts on its users.

In a post on the company’s security blog, Google’s Product Manager of Account Security Jonathan Skelker announced that the search giant will begin to block account sign-ins from embedded browsers within applications.

The problem with embedded browsers, as Skelker lays out, is that it leaves Google’s users susceptible to phishing attacks from bad actors.

Previously, third-party developers could add web browser instances, like the Chromium Embedded Framework, to their apps. This allowed users to log into a service with their existing Google account without having to sign-up for a fresh account on a brand new platform.

While embedded browsers may have made it easy for an app user to sign-up or login, it also made it just as simple for a hacker to carry out a man-in-the-middle phishing attack. Malicious actors could use embedded browser frameworks to essentially eavesdrop on an unsuspecting user and steal their login credentials.

Unfortunately, Google can’t differentiate between legitimate sign-ins and a phishing attack through embedded browser frameworks. Because of this, the company has decided to ban this login method outright.

The company is urging developers using embedded browsers to switch to browser-based OAuth authentication. Basically, when a user wants to login to a third-party app using their Google account, the app would open up the Google sign-in page through their mobile browser. This way users can view the URL of the site to ensure this is a legitimate Google page and not a phishing website imposter.

Google says it will begin blocking sign-ins from embedded browser frameworks in June.

Mashable Potato

Recommended For You
Google debuts 'Me Meme' feature in Google Photos app
A sign of US technology company Google displayed during the World Economic Forum (WEF)

Sign up for The Farmer's Dog and get 60% off the first box for your furry friend
Two dogs waiting for food

Costco is giving away free $20 or $40 shop cards for new members
two costco shop cards on a pink and coral-colored background


Apple, Google agree to 'improve fairness' on app stores
Apple and Google logos

More in Tech
The Shark FlexStyle is our favorite Dyson Airwrap dupe, and it's $160 off at Amazon right now
The Shark FlexStyle Air Styling & Drying System against a colorful background.

Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

The best smartwatch you've never heard of is on sale for less than $50
Nothing CMF Watch 3 Pro in light green with blue and green abstract background

Reddit r/all takes another step into the grave
Reddit logo on phone screen

Take back your screen from ads and trackers with this $16 tool
AdGuard Family Plan: Lifetime Subscription

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


You can track Artemis II in real time as Orion flies to the moon
Victor Glover and Reid Wiseman piloting the Orion spacecraft
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!