-
Google is working on a Chrome feature that could block unwanted extensions on personal computers.
-
The planned protection targets extensions that change New Tab pages or default search engines.
-
Google may allow trusted organizations to bypass the protection when they need these controls.
Google is preparing a new security feature for Chrome that could stop some extensions from taking control of browser settings. The feature could block extensions that change the New Tab page or default search engine on unmanaged Windows and macOS computers. Google is developing the protection to fight abuse of Chrome’s enterprise policy system.
The system has legitimate uses in workplaces and other managed settings. However, malware can also abuse similar controls on personal computers. The proposed feature would help Chrome tell the difference between trusted management and unwanted changes.
Google Prepares New Chrome Protection
BleepingComputer first reported the planned feature after finding related changes in the Chromium Gerrit code review system.
The feature is linked to the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices flag. Google has not added the protection to Chrome’s stable release yet.
Google employee Anunoy Ghosh reportedly discussed the issue in a post cited by BleepingComputer. The post said attackers were abusing enterprise policies in “low-trust environments.”
The abuse can force users to use unwanted search engines or New Tab pages. The planned protection would target this type of activity on devices that organizations do not manage.
Chrome’s enterprise controls serve a useful purpose for businesses and other groups. Administrators can use them to install extensions and control how users access them.
Google’s Chrome Enterprise documentation explains how administrators can automatically install extensions. Some policies can also stop users from disabling or removing extensions. These controls work well when an organization manages the computer. The problem starts when malware uses similar settings on someone’s personal device.
Malware Can Abuse Enterprise Policies
According to reports, malware can add Chrome policy keys locally without the user’s permission. Attackers can then use those settings to force Chrome to install an extension. The extension may change the New Tab page or default search engine.
It can also redirect searches to other websites. The risks extend to enterprise platforms; a Claude Code exploit could give attackers persistent access to GitHub, Jira, and other enterprise tools.
Chrome may treat the extension as a policy-controlled tool, making it harder for users to remove. This abuse can also cause Chrome to show the “Managed by your organization” message on personal computers. The message can appear even when no employer or school controls the device.
Google’s planned feature would target this problem on unmanaged computers. Chrome would reportedly block policy-controlled extensions that try to change the New Tab page or default search engine. The browser could also record the extension’s ID as blocked. This would stop Chrome from repeatedly downloading the same extension during later policy checks.
Google is also considering protection for extensions that users install themselves. Those extensions would remain under the user’s control instead of later becoming locked by a policy setting.
The planned changes could also affect computers that once belonged to an organization. If a device loses its trusted management status, Chrome could remove certain affected extensions.
Those extensions would include ones that control the New Tab page or default search engine. The removal would happen when local policy settings remain after the device stops being managed.
Chrome Feature Still Under Development
The proposed protection remains under review, so Google could change how it works before release. BleepingComputer reported that Google also plans to collect data about policy-based hijacking attempts.
The company could use those figures to measure how often the protection blocks such attempts. Google may also provide an option for legitimate organizations to turn off the protection. That option would help businesses that use trusted extensions to control New Tab pages or default search engines.
Other technology websites have also reported on Google’s planned change. GHacks, RS Web Solutions and SecNews have covered the development. Those reports mainly point back to the original findings from BleepingComputer. The planned protection therefore remains a work in progress.
Chrome users should note that Google has not yet made the feature part of the stable browser. The company still needs to complete its review before the protection can reach regular Chrome users.
For now, the proposed change focuses on a specific problem. It aims to stop policy-controlled extensions from taking over key browser settings on unmanaged computers.
Google’s planned defense could give Chrome users more control over their New Tab pages and search engines. However, users will need to wait for the feature to reach the stable browser before it becomes a standard Chrome protection.