Google is rolling out end-to-end encryption for Gmail on iOS and Android to enterprise users. The feature lets Workspace users compose and read encrypted emails directly in the Gmail app without additional tools.
Google has expanded its client-side encryption offering to mobile platforms, bringing end-to-end encryption (E2EE) to Gmail users on iOS and Android devices. The rollout targets enterprise customers using Google Workspace.
■ Direct Integration
Eligible users can compose and read encrypted emails directly within the native Gmail app. This eliminates the need for separate applications or web portals to access encrypted messages.
■ Expanding Existing Features
The mobile rollout follows Google's introduction of E2EE for Gmail on the web, which launched over a year ago. Client-side encryption (CSE) gives organizations control over encryption keys and the identity service used to access those keys.
With E2EE enabled, email content is encrypted before it reaches Google's servers. Only the sender and intended recipients can decrypt and read the messages. Google cannot access the plaintext content of encrypted emails.
■ Enterprise Focus
The feature remains limited to Google Workspace enterprise users. Organizations must enable client-side encryption in their Workspace admin console before users can access the functionality.
Workspace editions that support CSE include Enterprise Plus, Education Plus, and Education Standard. The feature is not available to personal Gmail accounts or basic Workspace tiers.
■ Gradual Deployment
Google is implementing a gradual rollout schedule. The feature may take up to 15 days to become visible to all eligible users after initial deployment begins in their organization.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.
Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.