Google Enhances Chrome’s Security with New Feature
In a proactive stride towards bolstering browser security, Google is set to introduce a new feature within Chrome designed to prevent policy-installed extensions from tampering with the New Tab page or altering the default search engine settings.
BleepingComputer has identified this initiative through a series of ongoing changes within the Chromium Gerrit, although it has yet to be officially implemented. Google intends to activate this feature once the alterations receive approval.
Anunoy Ghosh, a Google employee, articulated the dilemma in a post: “In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are exploited to cement the grip of search engine or New Tab page hijackers.”
This forthcoming change activates the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default. This will initiate comprehensive blocking measures targeting unmanaged PCs operating on Windows and macOS systems.
At present, Chrome permits organizations to deploy enterprise policies that enforce the installation of extensions and regulate browser settings.
While this serves a legitimate purpose on properly managed devices linked to a domain or MDM (Mobile Device Management) system, it has been misappropriated by malware on standard consumer machines.
Malicious software can surreptitiously implant local Chrome policy keys, leading to the illicit installation of extensions that replace the New Tab page, modify the search engine, or redirect queries to dubious websites.
This manipulation can mislead Chrome into concluding that the extension was installed by an administrator, which complicates efforts to remove or disable it.
Users may encounter perplexing notifications, such as “Managed by your organization,” despite the absence of genuine organizational oversight.
Google deems these consumer PCs as “low-trust” environments, given that Chrome accesses locally stored policies without verification from a trustworthy entity, such as a domain or MDM service.
The proposed security feature aims to thwart attempts to install policy-controlled extensions that would override the New Tab page or the default search engine.
Under this new protocol, Chrome will abort the installation of such extensions, logging their IDs in a blocked-extension preference.
Moreover, Chrome will refrain from attempting to download the same blocked extension during subsequent policy verifications, thus averting repeated installation efforts and unnecessary network traffic.
Addressing Malware Tactics
Google is also counteracting another tactic employed by malicious software: extensions manually installed by users will no longer be transmuted into locked, policy-controlled extensions. Users will retain the ability to disable or uninstall them.
Should a previously managed device lose its trusted status while still bearing local policy keys, Chrome will automatically uninstall any extensions that override the New Tab and search engine settings.
To further enhance security, Google plans to introduce metrics that will track the prevalence of these policy-based hijackers and the frequency of Chrome’s blocking actions.

Legitimate administrators will be afforded access to an escape-hatch policy that can disable this protective feature when necessary, allowing authorized enterprise extensions to override the New Tab page or search engine settings.
It is important to note that these Gerrit changes are still undergoing review, and thus, the feature is not yet available in the stable version of Chrome.
Source link: Bleepingcomputer.com.




