TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/Google Chrome Moves to Block New Tab Hijacker Extensions by Default
News

Google Chrome Moves to Block New Tab Hijacker Extensions by Default

Google is building a Chrome fix for malware that abuses enterprise policy keys to hijack the New Tab page and default search engine on unmanaged PCs.

August 2, 2026 4 Min Read
35

Google is building a new Chrome defense against one of the browser’s most persistent hijacking tricks: malware that pretends to be an enterprise administrator so it can lock a malicious extension in place. BleepingComputer spotted the work on August 2, 2026, in a chain of Chromium code review changes still marked work in progress and not yet shipped to stable Chrome.

Table Of Content

  • How the Hijack Works Today
  • What the New Protection Does
  • Part of a Bigger Search Hijacking Problem

How the Hijack Works Today

Chrome gives IT departments a legitimate way to force install extensions and lock down browser settings on company owned computers through enterprise policy. On a properly managed, domain joined or MDM enrolled machine, that is exactly how it is supposed to work. The catch is that Chrome checks for the presence of local policy keys, not for proof that a real administrator set them. Malware that writes those same keys into an unmanaged consumer PC’s registry can trick Chrome into treating a hijacking extension as an admin deployment, one the person using the computer cannot disable or remove. Some victims even see Chrome’s “Managed by your organization” notice on a PC that has never been managed by anyone.

That is not a hypothetical. Research from threat intelligence firm d3lab, reported by Cyberpress in June 2026, traced a malware campaign that opened with a phishing email carrying a disguised script attachment. Once a victim opened it, the script dropped a legitimately signed Epic Games executable alongside a malicious DLL, a technique known as DLL side loading, to quietly launch PowerShell without tripping antivirus alerts. That PowerShell script rewrote the ExtensionInstallAllowlist and ExtensionInstallSources policy keys in the Windows registry to silently force install an extension called “Cloud vn105rkj64.” The extension then used Chrome’s Native Messaging feature, the same mechanism legitimate tools like password managers use to talk to the operating system, as a bridge to a remote command server that could run PowerShell commands on the infected machine.

What the New Protection Does

The fix is controlled by a feature flag named kBlockDseNtpOverrideExtensionsOnUnmanagedDevices. DSE is documented shorthand for Default Search Engine inside Chrome’s own source tree, where Chromium’s New Tab Page code notes that which page variant a user sees “is selected according to the user’s Default Search Engine (DSE), profile, extensions and policies.”

According to Google engineer Anunoy Ghosh, who wrote the description on the Gerrit change BleepingComputer found: “In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are abused to lock in search engine or new tab page hijackers.” Ghosh added: “This CL enables the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default, activating the end-to-end blocking defense on unmanaged Windows and macOS devices.”

Once active by default, Chrome would:

  • Cancel installation of any policy installed extension that tries to override the New Tab page or the default search engine, instead of letting it through
  • Save the blocked extension’s ID so Chrome stops retrying the same install on every future policy check, cutting down on repeated background network activity
  • Leave manually installed extensions alone. A person’s own choices stay under their own control and are never converted into locked policy extensions
  • Automatically remove an affected New Tab or search hijacking extension if a device later loses its managed status but still has leftover local policy keys

Google is also adding metrics to measure how often these hijackers actually appear, and giving legitimate administrators an escape hatch policy so a genuinely required enterprise extension can still override the New Tab page or search settings without being blocked.

Part of a Bigger Search Hijacking Problem

Policy key abuse is only one route to the same prize. Separate Cyberpress reporting on research from IntCyberDigest and the MalExt Sentry scanner describes a campaign called SearchJack: twenty-three Chrome Web Store extensions, disguised as tools for satellite imagery, productivity, news, and maps, that used the manifest’s settings override key to quietly reroute roughly 758,000 users’ search queries through at least eight monetization brokers before returning any results. That campaign does not touch enterprise policy at all, since it hides inside extensions published directly to the Chrome Web Store, which makes it a different abuse path than the one Google’s new Gerrit change targets. Together, the two campaigns show why Chrome keeps treating New Tab and search engine control as a security boundary worth defending on more than one front.

For IT teams, the scope of the new protection is worth noting closely. It only changes default behavior on devices Chrome does not consider managed, so properly enrolled corporate laptops are unaffected, and administrators keep a documented way to force install extensions that legitimately need to touch the New Tab page or search settings. The underlying Gerrit changes are still under review, so Google has not published a shipping timeline, but the direction closes a loophole malware has used for years to borrow the trust normally reserved for a real IT department.

Tags:

Browser SecurityEnterprise SecurityGoogleGoogle ChromeMalware

Share

Close-up of large rusted cast-iron gears meshing together inside an old mining dredge
Previous Post

How to Catch Hidden Bugs in Rust With Property-Based Testing and proptest

European Union flags flying outside the glass facade of the European Commission's Berlaymont building in Brussels
Next Post

The EU AI Act’s Article 50 Deadline Turns AI Disclosure Into an Accountability Test

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026