Google Enhances Chrome Security to Combat Extension Hijacking
Google is poised to unveil a significant security enhancement for Chrome, designed to thwart unauthorized policy-installed extensions from commandeering the New Tab page or altering the default search engine settings.
As reported by BleepingComputer, this innovative safeguarding measure has been identified within an array of ongoing modifications in Chromium Gerrit.
Although the feature has yet to be deployed, Google intends to enable it as a default setting following the requisite approvals.
Anunoy Ghosh, a Google representative, noted in a post, “In low-trust environments (unmanaged consumer devices), enterprise policy enforcement often becomes a vector for exploitation, locking users into search engine or New Tab page hijackers.”
This latest change activates the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default, instituting comprehensive blocking mechanisms on unmanaged devices running Windows and macOS.
Currently, Chrome permits organizations to impose enterprise policies that facilitate the forced installation of extensions and govern browser settings.
While this is generally beneficial for adequately administered work devices linked to a domain or mobile device management system, the same features have become tools of malice on standard consumer PCs.
Malware can surreptitiously add local Chrome policy keys, thus enforcing the installation of an extension that modifies the New Tab page, alters the default search engine, or redirects users to dubious websites.
Consequently, Chrome might erroneously recognize the extension as installed by an administrator, which complicates removal or deactivation efforts.
Moreover, users may encounter the perplexing notification stating, “Managed by your organization,” despite the device not being affiliated with any organizational management.
Google categorizes these consumer devices as “low-trust” environments, as Chrome processes locally stored policies without confirmation from a credible authority, such as a domain or MDM service.
Under the proposed protection measures, Chrome would effectively obstruct installations of policy-modified extensions that seek to override the New Tab page or alter the default search engine. The installation attempts would be aborted, with Chrome retaining the extension ID in a blocked-extension registry.
Additionally, Chrome would cease attempts to download any previously blocked extension during subsequent policy evaluations, thereby averting recurrent installation endeavors and reducing unnecessary network traffic.
Google Tackles Additional Malware Exploits
Extensions installed manually would now remain under user control and would not be converted into locked, policy-governed extensions, allowing users the liberty to disable or uninstall them at will.
Should a previously managed device lose its trusted management status yet retain local policy keys, Chrome will automatically remove affected New Tab and search-engine override extensions.
To augment its defenses, Google is also incorporating metrics to quantify the frequency of these policy-driven hijackers and the instances in which Chrome successfully blocks them.

Legitimate administrators will have the option to utilize an escape-hatch policy, which disables the protection feature when an essential enterprise extension necessitates overriding the New Tab page or search engine.
It is essential to note that these Gerrit changes remain under review, and the feature is not yet accessible in the stable version of Chrome.
Source link: Bleepingcomputer.com.



