SharkyDarky
Newbie
- Jul 27, 2026
- 3
- 0
Google is showing an unfamiliar Chrome session on my account even though i use an authenticator app. if it really was someone else, i'm trying to work out what could still be left behind after changing the password.
i'm planning to sign out every device, remove old OAuth apps and app passwords, regenerate the backup codes, check Gmail forwarding and filter rules, confirm the recovery email and phone, and then add a passkey.
after doing that, could an OAuth grant, app password, Chrome sync session or changed recovery setting still let them back in? does Google's “sign out all devices” actually revoke everything, or is there another place i should check to make sure the old access is dead?
i'm planning to sign out every device, remove old OAuth apps and app passwords, regenerate the backup codes, check Gmail forwarding and filter rules, confirm the recovery email and phone, and then add a passkey.
after doing that, could an OAuth grant, app password, Chrome sync session or changed recovery setting still let them back in? does Google's “sign out all devices” actually revoke everything, or is there another place i should check to make sure the old access is dead?