Google Chrome Moves to Block New Tab Hijacker Extensions by Default
Google is building a Chrome fix for malware that abuses enterprise policy keys to hijack the New Tab page and default search engine on unmanaged PCs.
Google is building a new Chrome defense against one of the browser’s most persistent hijacking tricks: malware that pretends to be an enterprise administrator so it can lock a malicious extension in place. BleepingComputer spotted the work on August 2, 2026, in a chain of Chromium code review changes still marked work in progress and not yet shipped to stable Chrome.
Table Of Content
How the Hijack Works Today
Chrome gives IT departments a legitimate way to force install extensions and lock down browser settings on company owned computers through enterprise policy. On a properly managed, domain joined or MDM enrolled machine, that is exactly how it is supposed to work. The catch is that Chrome checks for the presence of local policy keys, not for proof that a real administrator set them. Malware that writes those same keys into an unmanaged consumer PC’s registry can trick Chrome into treating a hijacking extension as an admin deployment, one the person using the computer cannot disable or remove. Some victims even see Chrome’s “Managed by your organization” notice on a PC that has never been managed by anyone.
That is not a hypothetical. Research from threat intelligence firm d3lab, reported by Cyberpress in June 2026, traced a malware campaign that opened with a phishing email carrying a disguised script attachment. Once a victim opened it, the script dropped a legitimately signed Epic Games executable alongside a malicious DLL, a technique known as DLL side loading, to quietly launch PowerShell without tripping antivirus alerts. That PowerShell script rewrote the ExtensionInstallAllowlist and ExtensionInstallSources policy keys in the Windows registry to silently force install an extension called “Cloud vn105rkj64.” The extension then used Chrome’s Native Messaging feature, the same mechanism legitimate tools like password managers use to talk to the operating system, as a bridge to a remote command server that could run PowerShell commands on the infected machine.
What the New Protection Does
The fix is controlled by a feature flag named kBlockDseNtpOverrideExtensionsOnUnmanagedDevices. DSE is documented shorthand for Default Search Engine inside Chrome’s own source tree, where Chromium’s New Tab Page code notes that which page variant a user sees “is selected according to the user’s Default Search Engine (DSE), profile, extensions and policies.”
According to Google engineer Anunoy Ghosh, who wrote the description on the Gerrit change BleepingComputer found: “In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are abused to lock in search engine or new tab page hijackers.” Ghosh added: “This CL enables the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default, activating the end-to-end blocking defense on unmanaged Windows and macOS devices.”
Once active by default, Chrome would:
- Cancel installation of any policy installed extension that tries to override the New Tab page or the default search engine, instead of letting it through
- Save the blocked extension’s ID so Chrome stops retrying the same install on every future policy check, cutting down on repeated background network activity
- Leave manually installed extensions alone. A person’s own choices stay under their own control and are never converted into locked policy extensions
- Automatically remove an affected New Tab or search hijacking extension if a device later loses its managed status but still has leftover local policy keys
Google is also adding metrics to measure how often these hijackers actually appear, and giving legitimate administrators an escape hatch policy so a genuinely required enterprise extension can still override the New Tab page or search settings without being blocked.
Part of a Bigger Search Hijacking Problem
Policy key abuse is only one route to the same prize. Separate Cyberpress reporting on research from IntCyberDigest and the MalExt Sentry scanner describes a campaign called SearchJack: twenty-three Chrome Web Store extensions, disguised as tools for satellite imagery, productivity, news, and maps, that used the manifest’s settings override key to quietly reroute roughly 758,000 users’ search queries through at least eight monetization brokers before returning any results. That campaign does not touch enterprise policy at all, since it hides inside extensions published directly to the Chrome Web Store, which makes it a different abuse path than the one Google’s new Gerrit change targets. Together, the two campaigns show why Chrome keeps treating New Tab and search engine control as a security boundary worth defending on more than one front.
For IT teams, the scope of the new protection is worth noting closely. It only changes default behavior on devices Chrome does not consider managed, so properly enrolled corporate laptops are unaffected, and administrators keep a documented way to force install extensions that legitimately need to touch the New Tab page or search settings. The underlying Gerrit changes are still under review, so Google has not published a shipping timeline, but the direction closes a loophole malware has used for years to borrow the trust normally reserved for a real IT department.








No Comment! Be the first one.