Google is testing a requirement for fingerprint or face scans before Chrome autofills saved passwords. After testing and pulling the feature over a year ago, Google revived it in the latest Chrome Canary build. The extra verification could prevent someone with an unlocked device from accessing all your saved website passwords.
Chrome on Android might soon be a little less trusting with password autofill. It looks like Google is testing a biometric check for stored passwords in Chrome that would require your fingerprint, face unlock, or another supported method of confirming that it’s really you before Chrome auto-fills the password. That change is back in the latest Chrome Canary build, with Google adding a “Biometric reauth for password filling” flag, first spotted by @Leopeva64 on X.
When enabled, tapping a saved credential can trigger authentication before Chrome hands over the password. Thus, unlocking your phone may no longer be enough to unlock your entire password vault. That extra step closes a security hole in Google Password Manager. While this security check is already available in apps for filling passwords with biometric protection, Chrome has handled autofill in the browser differently in the past.
Interestingly, there is already biometric authentication for password autofill on iPhones. On Apple's devices, Face ID or Touch ID can authenticate Password Auto Fill when you fill saved usernames and passwords in Safari. If Google does ship the feature, it would mean stealing an unlocked phone wouldn’t automatically provide you with access to every saved website password. For now, though, Chrome Canary is the testing ground, and Google hasn't announced a stable release date.
Source: Android Central · Summarized by HeadlinesBriefing