Chrome – New Tab Hijack Extensions

Overview

Google is preparing a new Chrome security feature designed to stop malicious extensions from hijacking the New Tab page or changing the default search engine. This protection, spotted in Chromium Gerrit changes, will be enabled by default once approved, marking a significant step in defending consumer devices against policy‑based extension abuse.

The Problem Today

  • Enterprise policies allow organizations to force‑install extensions and control browser settings.
  • Malware exploits this by adding local Chrome policy keys without user consent.
  • Chrome then treats the extension as “administrator‑installed,” preventing removal or disabling.
  • Victims often see the misleading “Managed by your organization” message, even though their PC is not managed.

Google’s Proposed Protection

  • Feature flag: kBlockDseNtpOverrideExtensionsOnUnmanagedDevices.
  • Scope: Applies to unmanaged consumer devices (Windows, macOS).
  • Defense:
    • Blocks policy‑controlled extensions that override New Tab or search engine.
    • Cancels installation attempts and saves the extension ID in a blocked list.
    • Prevents repeated downloads during future policy checks.
  • Manual installs remain safe: Extensions you install yourself will stay under your control.
  • Auto‑uninstall: If a device loses trusted management status, Chrome will remove affected hijacker extensions automatically.

Why It Matters

  • Low‑trust environments: Consumer PCs are vulnerable because Chrome reads local policies without verifying them against a domain or MDM.
  • Hijacker extensions: Redirect searches, replace New Tab pages, and funnel traffic to suspicious sites.
  • User impact: Prevents confusion, restores control, and reduces unnecessary network activity.

Additional Safeguards

  • Metrics: Chrome will track how often policy‑based hijackers appear and how frequently they’re blocked.
  • Escape hatch: Legitimate administrators can disable the protection if required enterprise extensions override New Tab or search engine.
  • Malware tricks addressed: Extensions installed manually will no longer be converted into locked policy‑controlled extensions.

Expert in the Cloud Insight

This move reflects a broader trend: browser security must evolve to counter supply‑chain style abuses. By blocking hijacker extensions at the policy level, Chrome is reclaiming user control in environments where malware has blurred the line between legitimate enterprise management and malicious manipulation. For defenders, the lesson is clear: visibility into extension behavior is as critical as patching vulnerabilities.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.