Respond to a Saved-Password Warning by Changing the Actual Account Password
A warning about a saved password needs an account-level response. Editing or deleting the entry in a password manager does not by itself change the password accepted by the website. Begin by confirming the warning through a trusted route.
Verify the alert and identify the account
Open Google Password Manager or go directly to its Password Checkup rather than following a link in an unexpected message. Google recommends this direct check to confirm a notification is authentic. Note the affected website and username, keeping the password itself out of notes and screenshots.
Distinguish a compromised-password warning from a reused or weak-password warning. They identify related but different problems. For a shared business account, coordinate with its responsible owner so a password change does not silently interrupt another authorised person or service.
Navigate independently to the genuine website and use its account-security process to set a unique new password. Follow its normal verification requirements. If you cannot access the account, use that service’s official recovery route rather than repeatedly altering the local saved entry.
Verify the new credential works
Update the intended password-manager entry when prompted, checking the website and username. Test a fresh authorised sign-in with the new credential before discarding your working recovery route. If several saved entries have similar names, identify the one that actually belongs to this account.
Where the old password was reused, change those other accounts through their own security settings as well. Changing one website does not rotate a password on another. Review the service’s available account-activity and recovery controls if there are signs of unauthorised use.
Return to Password Checkup to review the result, allowing for any update delay. Dismissing a warning only changes its display; it is not evidence that the website credential was changed. Record the account and completion date without retaining the old or new password in a support ticket. Escalate unresolved access or suspicious activity to the account owner.
Sources: Chrome documentation.