← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Google Chrome to Block New Tab and Search Engine Hijacking by Policy-Installed Extensions

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Chrome will block policy-installed extensions from hijacking New Tab or search engine.
  • The feature targets unmanaged Windows and macOS consumer devices.
  • Malware currently abuses enterprise policy features for forced extension installs.
  • Manually installed extensions will remain user-controlled, not locked by policy.

New Security Feature for Chrome

Google is developing a new security feature for its Chrome browser designed to prevent malicious extensions from taking over the New Tab page or altering the default search engine. This protection will specifically target extensions that are force-installed via policy on unmanaged consumer devices.

Addressing Malware Abuse

Currently, Chrome allows organizations to use enterprise policies to manage browser settings and force-install extensions. While beneficial for managed work environments, malware has exploited this functionality on consumer PCs. Malicious programs can add local Chrome policy keys without user permission, leading to the forced installation of extensions that redirect searches or change the New Tab page, often making them difficult to remove.

How the Protection Works

The proposed protection will block attempts to install policy-controlled extensions that try to override the New Tab page or default search engine. If such an installation is attempted, Chrome will cancel it and save the extension ID in a blocked-extension preference. This mechanism will also prevent Chrome from repeatedly trying to download the same blocked extension during future policy checks, reducing unnecessary network activity.

User Control and Device Management

Google refers to consumer PCs where these abuses occur as “low-trust” environments because Chrome reads locally stored policies without verification from a trusted authority like a domain or Mobile Device Management (MDM) service. Additionally, the update ensures that extensions installed manually by a user will remain under their control and will not be converted into locked, policy-controlled extensions, allowing users to disable or remove them as needed.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Google is implementing a new security feature in Chrome that will block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged consumer devices. This change addresses malware abuse that uses enterprise policy features to force-install malicious extensions, improving user control and browser security.