By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Google Chrome to Block New Tab Hijacking Extensions
Google is implementing a new security measure within its Chrome browser designed to thwart extensions that hijack the New Tab page or modify the default search engine. This forthcoming feature aims to protect users from unwanted alterations to their browsing experience, which are often initiated by policy-installed extensions. These extensions, typically deployed through enterprise management policies, have been observed to redirect users to specific websites upon opening a new tab or to change their default search provider without explicit consent.
The development addresses a persistent issue where malicious or unwanted extensions can compromise user autonomy and security. By default, Chrome currently allows extensions to modify these settings if they are installed via organizational policies, a mechanism intended for legitimate IT administration. However, this has created an avenue for abuse, where such policies might be exploited to push extensions that serve advertising, track user activity, or redirect to phishing sites. The proposed change would introduce a default blocking mechanism for these specific functionalities, requiring explicit user permission or a more stringent verification process for extensions attempting to alter the New Tab page or default search engine settings.
This initiative aligns with Google's ongoing efforts to enhance browser security and user privacy. In recent years, the company has introduced several features to give users more control over their browsing data and to combat malicious software. These include improvements to Safe Browsing, enhanced cookie controls, and more transparent permission management for websites and extensions. The blocking of New Tab hijackers is a direct response to user feedback and security research highlighting the prevalence and impact of such intrusive extension behaviors. The exact timeline for the rollout of this feature has not been specified, but it is expected to be integrated into a future stable release of Google Chrome.
While the specifics of the implementation are still under wraps, the core functionality will likely involve a more robust vetting process for extensions that request permissions to modify critical browser settings. This could include requiring extensions to declare their intent to change the New Tab page or search engine in their manifest file and undergo a review by Google. For enterprise environments, administrators may need to explicitly whitelist or configure approved extensions that require these permissions, ensuring that legitimate management tools can still function while preventing unauthorized changes. This proactive approach aims to fortify Chrome against a common vector of browser manipulation and reinforce user trust in the platform's security.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.