Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Foldables are sort of boring now — and that’s great news for Apple
    • Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets
    • Mathematicians prove perfectly fair elections are impossible
    • The Guardian view on global corporate tax: a $500bn prize that states must seize | Editorial
    • Two helicopters collide outside Athens as Greece battles to control wildfires | Greece
    • Sophie Woods completes Via Alpina endurance challenge in record 29 days
    • ‘Stench of sleaze’: Farage struck deal over political return months before 2024 election, reports say | Reform UK
    • Europe’s weak reaction to Spain’s migrant crisis
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Chrome may soon block New Tab hijacker extensions by default

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 2, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.

    BleepingComputer spotted the protection in a chain of work-in-progress Chromium Gerrit changes. It has not shipped yet, but Google plans to enable it by default once the changes are approved.

    “In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are abused to lock in search engine or new tab page hijackers,” Anunoy Ghosh, who works at Google, wrote in a post.

    image

    “This CL enables the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default, activating the end-to-end blocking defense on unmanaged Windows and macOS devices.”

    Right now, Chrome allows organizations to use enterprise policies to force-install extensions and control browser settings.

    It’s not exactly bad on properly managed work devices connected to a domain or mobile device management system, but malware has been abusing the same feature on regular consumer PCs.

    A malicious program can add local Chrome policy keys without your permission and force-install an extension that replaces the New Tab page, changes your search engine, or redirects searches to suspicious websites.

    Chrome may then believe that the extension was installed by an administrator, which prevents you from removing or disabling it.

    In some cases, Chrome also displays the confusing “Managed by your organization” message, even though the PC is not actually owned or managed by an organization.

    Google describes these consumer PCs as “low-trust” environments because Chrome is reading policies stored locally without confirmation from a trusted authority, such as a domain or MDM service.

    Under the proposed protection, Chrome would block attempts to install policy-controlled extensions that override the New Tab page or default search engine.

    The installation would be canceled, and Chrome would save the extension ID in a blocked-extension preference.

    Chrome would also stop trying to download the same blocked extension during future policy checks, which should prevent repeated installation attempts and unnecessary network activity.

    Google is also addressing another trick used by malware

    An extension that you installed manually would no longer be converted into a locked, policy-controlled extension. It would remain under your control, so you could still disable or remove it.

    If a previously managed device loses its trusted management status but still has local policy keys, Chrome would automatically uninstall affected New Tab and search-engine override extensions.

    Google is adding metrics to measure how often these policy-based hijackers appear and how frequently Chrome blocks them.

    Legitimate administrators would also have access to an escape-hatch policy that disables the protection when a required enterprise extension overrides the New Tab page or search engine.

    The Gerrit changes are still under review, so the feature is not available in stable Chrome yet.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    block Chrome Default extensions Google hijacker Tab
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI Company Sues Town for Trying to Block Data Center Near National Park

    FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

    SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

    Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

    Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    The Guardian view on global corporate tax: a $500bn prize that states must seize | Editorial

    August 2, 2026
    Latest Posts

    Oil has harmed the nature and people of the Niger Delta; human rights may save it

    July 23, 2026

    Drought announcement looms for parts of Wales over river levels

    July 23, 2026

    Swiss Bank BancaStato Launches Bitcoin Trading Through Sygnum And Avaloq

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.