Vulnerabilities

Chrome to Block New Tab Hijacker Extensions

August 2, 2026 16:00 · 10 min read
Chrome to Block New Tab Hijacker Extensions

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. This protection was spotted in a chain of work-in-progress Chromium Gerrit changes and has not shipped yet, but Google plans to enable it by default once the changes are approved.

Background

Currently, Chrome allows organizations to use enterprise policies to force-install extensions and control browser settings. While this is not a problem on properly managed work devices connected to a domain or mobile device management system, malware has been abusing the same feature on regular consumer PCs. A malicious program can add local Chrome policy keys without permission and force-install an extension that replaces the New Tab page, changes the search engine, or redirects searches to suspicious websites.

Chrome may then believe that the extension was installed by an administrator, which prevents the user from removing or disabling it. In some cases, Chrome also displays the confusing “Managed by your organization” message, even though the PC is not actually owned or managed by an organization. Google describes these consumer PCs as “low-trust” environments because Chrome is reading policies stored locally without confirmation from a trusted authority, such as a domain or MDM service.

Proposed Protection

Under the proposed protection, Chrome would block attempts to install policy-controlled extensions that override the New Tab page or default search engine. The installation would be canceled, and Chrome would save the extension ID in a blocked-extension preference. Chrome would also stop trying to download the same blocked extension during future policy checks, which should prevent repeated installation attempts and unnecessary network activity.

Google is also addressing another trick used by malware: an extension that the user installed manually would no longer be converted into a locked, policy-controlled extension. It would remain under the user's control, so they could still disable or remove it. If a previously managed device loses its trusted management status but still has local policy keys, Chrome would automatically uninstall affected New Tab and search-engine override extensions.

Metrics and Escape Hatch

Google is adding metrics to measure how often these policy-based hijackers appear and how frequently Chrome blocks them. Legitimate administrators would also have access to an escape-hatch policy that disables the protection when a required enterprise extension overrides the New Tab page or search engine.

The Gerrit changes are still under review, so the feature is not available in stable Chrome yet. As Anunoy Ghosh, who works at Google, wrote in a post, "In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are abused to lock in search engine or new tab page hijackers." The new feature aims to address this issue and provide better protection for Chrome users.

According to a Picus whitepaper, security teams log 54% of successful attacks and alert on just 14%. The rest move through the environment unseen. The whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free