unfamiliar google session even with 2FA

SharkyDarky

Newbie
Joined
Jul 27, 2026
Messages
3
Reaction score
0
Google is showing an unfamiliar Chrome session on my account even though i use an authenticator app. if it really was someone else, i'm trying to work out what could still be left behind after changing the password.
i'm planning to sign out every device, remove old OAuth apps and app passwords, regenerate the backup codes, check Gmail forwarding and filter rules, confirm the recovery email and phone, and then add a passkey.
after doing that, could an OAuth grant, app password, Chrome sync session or changed recovery setting still let them back in? does Google's “sign out all devices” actually revoke everything, or is there another place i should check to make sure the old access is dead?
 
Google is showing an unfamiliar Chrome session on my account even though i use an authenticator app. if it really was someone else, i'm trying to work out what could still be left behind after changing the password.
i'm planning to sign out every device, remove old OAuth apps and app passwords, regenerate the backup codes, check Gmail forwarding and filter rules, confirm the recovery email and phone, and then add a passkey.
after doing that, could an OAuth grant, app password, Chrome sync session or changed recovery setting still let them back in? does Google's “sign out all devices” actually revoke everything, or is there another place i should check to make sure the old access is dead?
Passkey this , passkey that ... But their not bullet proof Ya know .. After Changing Pass What Other Little Things Have You Done To Ensure Everything Is Secure ?
 
If you had 2FA enabled, my first suspicion would be a cookie stealer.

I'd treat the device as compromised, as well as all your other logged-in accounts. Do a force sign out on all your accounts, do a thorough scan (or even better, wipe and reinstall), then change your passwords after getting rid of the malware.
 
If you had 2FA enabled, my first suspicion would be a cookie stealer.

I'd treat the device as compromised, as well as all your other logged-in accounts. Do a force sign out on all your accounts, do a thorough scan (or even better, wipe and reinstall), then change your passwords after getting rid of the malware.
force sighn out means i must login everythings agin eh and u do this everyday or depends u care its not?
 
force sighn out means i must login everythings agin eh and u do this everyday or depends u care its not?
Do it once, clean your device, change your passwords, then relogin. As long as there's no malware left behind, it should only be a one time thing.
 
Do it once, clean your device, change your passwords, then relogin. As long as there's no malware left behind, it should only be a one time thing.
fully agreed,sometimes cleasing enough what you used for nasty btw ?
 
Back
Top