March 21, 2026

By PhishClean Research Team - browser security guidance based on phishing analysis, defensive research, and product work.

Fake Google Meet Updates Are Turning a Single Click Into Device Enrollment

A recent Malwarebytes report says a fake Google Meet update page is abusing a legitimate Windows device-enrollment mechanism. That makes the attack unsettling for a simple reason: no password theft is required at the start, and there may be no obvious malware prompt at all.

According to the report, the fake update page impersonates Google Meet well enough to pass a casual glance, then uses the ms-device-enrollment URI scheme to open a native Windows enrollment flow. If the victim keeps going, the machine can reportedly be enrolled into attacker-controlled management.

Instead of stealing credentials first, the attacker aims for control of the device itself.

This is phishing that leans on real operating-system workflows. The browser is just the handoff point.

Why this attack is different

Most people think phishing means a fake login page, a password prompt, or a malicious download. This reported campaign is different because it uses a legitimate Windows feature meant for IT provisioning.

Instead of seeing a suspicious executable, the victim sees a real system dialog. Native system prompts naturally feel safer than random browser pop-ups.

Why one click matters here

The click does not just open another webpage. It reportedly hands the browser session off to a trusted Windows workflow, which means many people will assume they are still moving through a legitimate update process.

The attacker is exploiting trust in the operating system itself, not only trust in a brand or domain.

What the report says the attacker gains

That is a very different risk profile from a simple credential phish.

What to do if you think you were affected

Open Windows Settings and review Accounts > Access work or school. Disconnect any unknown or suspicious enrollment immediately. Treat the device as potentially compromised and involve IT or incident response rather than assuming a password reset will fix the problem.

The browser remains the trust handoff point. If the fake update page does not get the click, the chain stops before Windows ever gets involved.

How to verify a meeting-update prompt is real

Google Meet runs in the browser - there is no separate desktop client that needs an update before you can join a call. That one fact defuses the entire lure: a page telling you Meet needs an update is asking you to do something the real product never does. The same logic covers most web apps. Browser-based tools update silently through the browser, and the browser itself updates through its own menu - never through a webpage you happened to land on.

When any update prompt interrupts you mid-task, close it and go to the source instead: open the application, or the browser's own About page, and check for updates there. A real update will still be waiting in five minutes. A lure depends on you acting before you check.

Why custom URI schemes are a phishing favorite

Links do not only open webpages. Schemes like mailto:, tel:, and vendor-specific handlers tell the browser to pass the request to another program on the machine. That handoff is what makes this class of attack attractive: the moment a native dialog opens, the suspicious address bar is out of sight and the operating system's trusted styling takes over. The dialog is genuine - it is simply being fed attacker-controlled input.

So treat the transition itself as the checkpoint. When a click on a webpage produces a system dialog you did not expect - enrollment, remote access, certificate installation, anything mentioning management - the safe response is to cancel, not to study the dialog for reassurance. It will always look legitimate, because it is a real dialog.

A quick checklist before approving any system prompt

Where browser-side detection helps

Because the handoff starts in the browser, the browser is also the cheapest place to break the chain. PhishClean analyzes the page you are actually on, locally - lookalike branding, suspicious hosting, fake update framing - before a convincing button can pass you into a system workflow. It is one layer against this whole class of phishing attacks, not just one campaign. And if you already clicked through something similar, work through what to do if you clicked a phishing link in addition to reviewing your enrollment settings.

Source note

This post is based on Malwarebytes' March 6 article One click on this fake Google Meet update can give attackers control of your PC.

Frequently Asked Questions

Why is the fake Google Meet update page dangerous?

Because it reportedly uses a legitimate Windows device-enrollment mechanism to open a real system workflow that can enroll the victim's PC into attacker-controlled management.

Why is this different from normal phishing?

The attack does not need to steal a password first or drop obvious malware. It abuses a legitimate operating-system feature and trusted management infrastructure instead.

What should someone do if they clicked and completed enrollment?

Treat the machine as potentially compromised, check Access work or school settings, disconnect any unknown enrollment, and involve IT or incident response immediately.

Catch fake update pages before they hand off trust

PhishClean helps detect suspicious pages and browser-level phishing signals before a single click moves into a much riskier workflow.

Install PhishClean Free

Share This Guide

If this helped, share it with someone who would benefit from it, or subscribe for new browser-security guides from PhishClean.