Chrome to block policy-installed extensions from hijacking New Tab page
Google is developing a security update to stop malware from using enterprise policies to force search engine redirects.
Google is developing a security update for Chrome designed to prevent extensions installed via enterprise policies from hijacking the New Tab page or altering the default search engine. The browser will identify attempts by these policy-controlled extensions to override core user settings and automatically block the changes.
According to BleepingComputer, Google is currently implementing metrics to track how often these policy-based hijackers appear and the overall effectiveness of the blocks. This data-driven approach allows the company to measure the prevalence of the attack vector before fully deploying the mitigation.
The Policy Loophole
Browser hijackers frequently exploit "policy-installed" methods to maintain a foothold on a user's system. These methods are typically reserved for corporate IT administrators to manage software across a fleet of devices. When malware uses this mechanism, it marks the malicious extension as "Installed by your organization," which effectively locks the settings and prevents the user from removing the extension through standard browser menus. This allows attackers to redirect user traffic to ad-heavy or malicious search engines without the user's consent.
Impact on Malware Persistence
This move closes a significant loophole used by malware and Potentially Unwanted Programs (PUPs) to monetize user traffic. By restricting the ability of policy-installed extensions to modify the New Tab page and search engine, Google reduces the effectiveness of a common persistence mechanism. Because these extensions often bypass standard user consent prompts, they have historically been a reliable way for attackers to ensure their redirects remain active even after a user attempts to clean their browser.
What to Watch
While the feature is in development, the current focus remains on the implementation of tracking metrics to quantify the scale of the problem. It remains to be seen how Google will handle legitimate enterprise needs that may require New Tab customization via policy, though the primary goal is to neutralize the specific behavior used by hijackers. Users should continue to monitor their extension lists for any "Installed by your organization" labels if they are not on a managed corporate device.