How to Turn on Compromised Password Alerts in Chrome: A Practical 2026 Guide

Written by: Abigail Ivy
Published on:

What compromised password alerts in Chrome do

Knowing how to turn on compromised password alerts in Chrome helps you catch reused or leaked credentials before they are abused in account takeovers.

Chrome uses Google Password Manager to compare saved passwords against known breach data and flags passwords that should be changed immediately.

This matters because attackers often test stolen credentials across email, banking, shopping, and social accounts within minutes of a leak.

Once the alert appears, you can update the password, review other saved logins, and reduce the risk of credential stuffing.

How to turn on compromised password alerts in Chrome

Chrome’s password warning feature works through Google Password Manager, so you need to be signed in to a Google account and syncing passwords on your device.

The exact menu labels can vary slightly by Chrome version, but the path is consistent on desktop and mobile.

  1. Open Chrome and sign in to your Google account.
  2. Click the three-dot menu and open Settings.
  3. Go to Password Manager or Autofill and passwords.
  4. Select Password Checkup or Check passwords.
  5. Enable alerts and allow Chrome to monitor your saved passwords for compromise.

On some versions, Chrome will ask you to turn on password sync first.

If sync is disabled, compromised password alerts may not appear because Chrome cannot compare all stored credentials across your signed-in devices.

Where to find the setting on desktop

On Windows, macOS, and Linux, the fastest route is usually through the Chrome profile menu.

Open the profile icon in the top-right corner, then go to the password manager and look for security check or password alert settings.

Common desktop paths

  • Chrome menu > Settings > Autofill and passwords > Google Password Manager
  • Profile icon > Passwords > Checkup
  • chrome://password-manager/password-checkup in the address bar, if supported by your version

If you manage multiple Google accounts, make sure the correct profile is active.

Password alerts are tied to the account and profile that saved the credentials.

How to enable alerts on Android and iPhone

Chrome on mobile can also show compromised password warnings, especially when Google Password Manager is turned on.

The interface is more compact, but the steps are similar.

  1. Open the Chrome app.
  2. Tap the three-dot menu and choose Settings.
  3. Tap Google Password Manager or Password Manager.
  4. Open Password Checkup or a similar security section.
  5. Turn on password alerts if the option is available.

On Android, alerts are often more integrated because Chrome and Google services work closely together.

On iPhone, you may need to confirm that Chrome is your preferred browser and that Google Password Manager is set up correctly to surface security warnings.

What to do when Chrome flags a compromised password

If Chrome reports a compromised password, treat it as urgent even if the account still seems secure.

The warning usually means the password appeared in a data breach, was exposed in a leak, or matches a credential known to attackers.

  • Change the password immediately on the affected site.
  • Use a unique, randomly generated password.
  • Update any other account that reused the same password.
  • Enable multifactor authentication, such as an authenticator app or passkey.
  • Review recent logins, recovery options, and connected devices.

For high-value accounts such as Gmail, Microsoft 365, Apple ID, PayPal, and banking portals, changing the password is only one step.

You should also verify recovery email addresses, phone numbers, and session activity to make sure an attacker did not already gain access.

Why password reuse makes alerts more important

Compromised password alerts are most useful when you have reused the same password across several services.

Credential stuffing attacks depend on that reuse, because once one password is exposed, attackers try the same email and password combination everywhere.

Chrome helps reduce that risk by identifying repeated passwords and warning you when one of them is compromised.

A strong password strategy still matters: every account should have its own unique password, ideally generated and stored in a password manager.

Best practices for stronger account security

  • Use a different password for every account.
  • Prefer long passphrases or generated passwords of 14 characters or more.
  • Turn on multifactor authentication wherever it is supported.
  • Keep recovery methods current and secured.
  • Review saved passwords regularly in Google Password Manager.

Why alerts may not appear

If you followed the steps for how to turn on compromised password alerts in Chrome and still do not see warnings, a few common settings may be blocking them.

Chrome needs access to your saved passwords and an active account connection to run the security check properly.

  • You are not signed in to Chrome with a Google account.
  • Password sync is off, limiting what Chrome can check.
  • Saved passwords are elsewhere, such as another password manager.
  • Outdated Chrome version is missing the latest Password Manager features.
  • Enterprise policies on a work device may disable the feature.

Updating Chrome, confirming sync, and checking the active profile usually resolves the issue.

If you use a managed device, your organization may control whether password warnings are available.

How Chrome compares with other password security tools

Chrome’s alerts are convenient because they are built into the browser and tied to Google Password Manager.

That makes them easy to use for everyday browsing, but they are not the only source of breach monitoring.

Dedicated password managers such as 1Password, Bitwarden, Dashlane, and LastPass also provide breach detection and security reports.

Their advantage is cross-browser coverage, which can be useful if you use Safari, Firefox, Edge, and Chrome on different devices.

For many users, Chrome alerts are a practical first line of defense.

Pairing them with a dedicated password manager, passkeys, and multifactor authentication creates a stronger security stack.

Fast checklist for setting up Chrome password alerts

  • Sign in to Chrome with your Google account.
  • Turn on password sync.
  • Open Google Password Manager.
  • Run Password Checkup.
  • Enable compromised password alerts if prompted.
  • Change flagged passwords right away.

Once the feature is active, Chrome can help surface risky passwords before they are used against you.

That makes the browser a useful monitoring layer, especially if you have many old accounts or have ever reused passwords across sites.

When to recheck your saved passwords

It is smart to run a manual password check after a major breach announcement, after switching devices, or after importing passwords from another browser.

Regular reviews help you catch older accounts that have been forgotten but still hold personal data, payment details, or recovery options.

If you make account security a routine, Chrome’s compromised password alerts become more effective because there is less risk to clean up.

The goal is not just to receive alerts, but to make sure every alert leads to a faster password change and a more secure account setup.