Google Chrome Could Soon Automatically Block Extensions That Hijack New Tabs

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Google Enhances Chrome’s Security with New Feature

In a proactive stride towards bolstering browser security, Google is set to introduce a new feature within Chrome designed to prevent policy-installed extensions from tampering with the New Tab page or altering the default search engine settings.

BleepingComputer has identified this initiative through a series of ongoing changes within the Chromium Gerrit, although it has yet to be officially implemented. Google intends to activate this feature once the alterations receive approval.

Anunoy Ghosh, a Google employee, articulated the dilemma in a post: “In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are exploited to cement the grip of search engine or New Tab page hijackers.”

This forthcoming change activates the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default. This will initiate comprehensive blocking measures targeting unmanaged PCs operating on Windows and macOS systems.

At present, Chrome permits organizations to deploy enterprise policies that enforce the installation of extensions and regulate browser settings.

While this serves a legitimate purpose on properly managed devices linked to a domain or MDM (Mobile Device Management) system, it has been misappropriated by malware on standard consumer machines.

Malicious software can surreptitiously implant local Chrome policy keys, leading to the illicit installation of extensions that replace the New Tab page, modify the search engine, or redirect queries to dubious websites.

This manipulation can mislead Chrome into concluding that the extension was installed by an administrator, which complicates efforts to remove or disable it.

Users may encounter perplexing notifications, such as “Managed by your organization,” despite the absence of genuine organizational oversight.

Google deems these consumer PCs as “low-trust” environments, given that Chrome accesses locally stored policies without verification from a trustworthy entity, such as a domain or MDM service.

The proposed security feature aims to thwart attempts to install policy-controlled extensions that would override the New Tab page or the default search engine.

Under this new protocol, Chrome will abort the installation of such extensions, logging their IDs in a blocked-extension preference.

Moreover, Chrome will refrain from attempting to download the same blocked extension during subsequent policy verifications, thus averting repeated installation efforts and unnecessary network traffic.

Addressing Malware Tactics

Google is also counteracting another tactic employed by malicious software: extensions manually installed by users will no longer be transmuted into locked, policy-controlled extensions. Users will retain the ability to disable or uninstall them.

Should a previously managed device lose its trusted status while still bearing local policy keys, Chrome will automatically uninstall any extensions that override the New Tab and search engine settings.

To further enhance security, Google plans to introduce metrics that will track the prevalence of these policy-based hijackers and the frequency of Chrome’s blocking actions.

Google Search Unveils AI Summaries for All Users in the U.S.

Legitimate administrators will be afforded access to an escape-hatch policy that can disable this protective feature when necessary, allowing authorized enterprise extensions to override the New Tab page or search engine settings.

It is important to note that these Gerrit changes are still undergoing review, and thus, the feature is not yet available in the stable version of Chrome.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Ranjana Banerjee

I’m Ranjana Banerjee, Creative Content Manager at RSWEBSOLS in Kolkata, India, with 10+ years of experience in blogging, SEO, digital marketing, and e-commerce. I create high-quality content and SEO strategies that boost traffic, improve rankings, and help businesses grow in competitive markets.
Share the Love
Related News Worth Reading