Skip to main content
Mallory
Back to stories
ai-platform-securityprivacy-surveillance-policy

Chrome Draws Scrutiny for Quietly Downloading 4GB Gemini Nano Model

Updated 10d agoFirst seen May 6, 20269 sources

Google Chrome is reportedly downloading a roughly 4GB file, weights.bin, onto some users’ devices as part of its on-device Gemini Nano AI features, prompting complaints that the transfer can occur without clear notice. Reports said the file appears in Chrome user data directories on eligible systems and may be fetched in the background during normal browsing, with one researcher citing a controlled macOS test and filesystem logs that showed Chrome creating the model directory and downloading the payload automatically.

The file is described as part of Chrome’s local AI stack rather than malware, enabling faster processing, offline capabilities, and reduced reliance on cloud services, but critics said users may not realize it has been installed and that deleting it alone may not stop it from returning. Coverage said the download is tied to Chrome’s On-device AI setting, and users seeking to remove it more permanently must delete the file and disable that feature; the practice has also triggered claims that silent multi-gigabyte downloads could raise transparency, privacy, bandwidth, cost, and environmental concerns, including possible scrutiny under EU privacy rules.

Share:
Chrome Draws Scrutiny for Quietly Downloading 4GB Gemini Nano Model
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the earliest known activity through the most recent confirmed update.

5 EVENTS
Feb 1, 20264mo ago

Google rolls out Chrome On-device AI disable toggle

Google began rolling out a Chrome Settings > System > On-device AI toggle in February 2026 that lets users disable and remove the Gemini Nano model. Google said that once the feature is disabled, the model will no longer download or update.

How to Disable Google's Gemini in Chrome | WIRED
May 6, 202612d ago

Google deploys Gemini Nano model download in Chrome

Google made a roughly 4GB on-device AI model file, weights.bin, part of Chrome's Gemini Nano feature set for some users. The file is associated with Chrome's On-device AI capability and may be stored in Chrome user data directories on eligible systems.

Researcher alleges Chrome silently downloads 4GB AI model

Security researcher Alexander Hanff reported that Chrome can create the model directory and download the weights.bin payload in the background without clear user notice or consent. He said a controlled macOS test with a fresh Chrome profile and filesystem event logs supported the claim.

Reports note deleted Gemini Nano file may be re-downloaded

Coverage on May 6, 2026 said users who remove the weights.bin file may see Chrome download it again unless they disable the relevant On-device AI setting or experimental flags. The reports also highlighted concerns about bandwidth use, transparency, and possible regulatory implications.

May 8, 202610d ago

Google changes Chrome 148 On-device AI toggle wording

In Chrome 148, Google removed wording from the On-device AI settings toggle that had said the model would not send data to Google servers, triggering new privacy concerns. Google said the text change did not reflect any change in how Chrome's on-device AI works and maintained that model processing remains local to the device.

Chrome's 4GB AI model isn't new, but you're not wrong for being confused - Ars Technica
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.