Google is taking a significant step towards protecting its Chrome browser users from malicious extensions that hijack their New Tab page and default search engine. A new security feature, currently under review, would block such extensions by default on unmanaged consumer devices, preventing them from being installed or executed.
This move comes in response to the increasing abuse of enterprise policies by malware on regular consumer PCs. These policies allow organizations to force-install extensions and control browser settings, but malicious programs can exploit this feature by adding local Chrome policy keys without user permission. This allows them to install extensions that replace the New Tab page, change search engines, or redirect searches to suspicious websites. Once installed, these extensions can be difficult to remove or disable, as Chrome may believe they were installed by an administrator.
Google describes consumer PCs that are not properly managed as “low-trust” environments because Chrome reads policies stored locally without confirmation from a trusted authority. Under the proposed protection, Chrome would block attempts to install policy-controlled extensions that override the New Tab page or default search engine. If such an extension is detected, its installation would be canceled, and Chrome would save its ID in a blocked-extension preference.
In addition to blocking these malicious extensions, Google is also addressing another trick used by malware. Extensions installed manually by users would no longer be converted into locked, policy-controlled extensions, giving users control over their own extensions and allowing them to disable or remove them as needed. If a previously managed device loses its trusted management status but still has local policy keys, Chrome would automatically uninstall affected New Tab and search-engine override extensions.
The new feature is not yet available in stable Chrome, but Google plans to enable it by default once the changes are approved. The Gerrit changes that implement this protection also include metrics to measure how often these policy-based hijackers appear and how frequently Chrome blocks them. Legitimate administrators would have access to an escape-hatch policy that disables the protection when a required enterprise extension overrides the New Tab page or search engine.
This move by Google highlights the importance of vigilance in protecting against browser-based threats. While many users may not be aware of the risks posed by malicious extensions, this feature demonstrates Chrome’s commitment to safeguarding its users and preventing abuse of its policies. As security teams know all too well, attacks can slip through detection if not properly tested. By staying one step ahead of attackers, we can prevent these threats from causing harm.
In conclusion, Google’s new feature is a significant development in the ongoing battle against browser-based malware. Users should be aware of the risks posed by malicious extensions and take steps to protect themselves, such as regularly reviewing their installed extensions and keeping their Chrome browser up to date with the latest security patches. By staying informed and taking proactive measures, we can prevent these threats from succeeding and keep our online environments secure.
Source: Bleeping Computer — 2026-08-02