Google Chrome is likely to automatically prevent New Tab hijacker extensions

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Google Enhances Chrome Security to Combat Extension Hijacking

Google is poised to unveil a significant security enhancement for Chrome, designed to thwart unauthorized policy-installed extensions from commandeering the New Tab page or altering the default search engine settings.

As reported by BleepingComputer, this innovative safeguarding measure has been identified within an array of ongoing modifications in Chromium Gerrit.

Although the feature has yet to be deployed, Google intends to enable it as a default setting following the requisite approvals.

Anunoy Ghosh, a Google representative, noted in a post, “In low-trust environments (unmanaged consumer devices), enterprise policy enforcement often becomes a vector for exploitation, locking users into search engine or New Tab page hijackers.”

This latest change activates the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default, instituting comprehensive blocking mechanisms on unmanaged devices running Windows and macOS.

Currently, Chrome permits organizations to impose enterprise policies that facilitate the forced installation of extensions and govern browser settings.

While this is generally beneficial for adequately administered work devices linked to a domain or mobile device management system, the same features have become tools of malice on standard consumer PCs.

Malware can surreptitiously add local Chrome policy keys, thus enforcing the installation of an extension that modifies the New Tab page, alters the default search engine, or redirects users to dubious websites.

Consequently, Chrome might erroneously recognize the extension as installed by an administrator, which complicates removal or deactivation efforts.

Moreover, users may encounter the perplexing notification stating, “Managed by your organization,” despite the device not being affiliated with any organizational management.

Google categorizes these consumer devices as “low-trust” environments, as Chrome processes locally stored policies without confirmation from a credible authority, such as a domain or MDM service.

Under the proposed protection measures, Chrome would effectively obstruct installations of policy-modified extensions that seek to override the New Tab page or alter the default search engine. The installation attempts would be aborted, with Chrome retaining the extension ID in a blocked-extension registry.

Additionally, Chrome would cease attempts to download any previously blocked extension during subsequent policy evaluations, thereby averting recurrent installation endeavors and reducing unnecessary network traffic.

Google Tackles Additional Malware Exploits

Extensions installed manually would now remain under user control and would not be converted into locked, policy-governed extensions, allowing users the liberty to disable or uninstall them at will.

Should a previously managed device lose its trusted management status yet retain local policy keys, Chrome will automatically remove affected New Tab and search-engine override extensions.

To augment its defenses, Google is also incorporating metrics to quantify the frequency of these policy-driven hijackers and the instances in which Chrome successfully blocks them.

A hand holding a smartphone displaying the Google search homepage on its screen.

Legitimate administrators will have the option to utilize an escape-hatch policy, which disables the protection feature when an essential enterprise extension necessitates overriding the New Tab page or search engine.

It is essential to note that these Gerrit changes remain under review, and the feature is not yet accessible in the stable version of Chrome.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Ranjana Banerjee

I’m Ranjana Banerjee, Creative Content Manager at RSWEBSOLS in Kolkata, India, with 10+ years of experience in blogging, SEO, digital marketing, and e-commerce. I create high-quality content and SEO strategies that boost traffic, improve rankings, and help businesses grow in competitive markets.
Share the Love
Related News Worth Reading