Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. This feature is aimed at protecting consumer PCs from malware that abuses enterprise policies to install m…
Intelligence analysis by Llama

Google Chrome may soon block New Tab hijacker extensions by default. This feature is aimed at protecting consumer PCs from malware that abuses enterprise policies to install malicious extensions. The feature would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.
Imagine you have a computer and someone installs a program that changes your browser's search engine or new tab page without your permission. This is called a 'hijacker' and it's a type of malware. Google is working on a new feature for its Chrome browser that would stop these hijackers from working. It would keep your search engine and new tab page safe and secure.
Analysis
A New Security Feature for Chrome
Google is preparing a new security feature for Chrome that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. This feature is aimed at protecting consumer PCs from malware that abuses enterprise policies to install malicious extensions.
The proposed protection would block attempts to install policy-controlled extensions that override the New Tab page or default search engine. The installation would be canceled, and Chrome would save the extension ID in a blocked-extension preference. Chrome would also stop trying to download the same blocked extension during future policy checks, which should prevent repeated installation attempts and unnecessary network activity.
Google is also addressing another trick used by malware. An extension that you installed manually would no longer be converted into a locked, policy-controlled extension. It would remain under your control, so you could still disable or remove it. If a previously managed device loses its trusted management status but still has local policy keys, Chrome would automatically uninstall affected New Tab and search-engine override extensions.
Google is adding metrics to measure how often these policy-based hijackers appear and how frequently Chrome blocks them. Legitimate administrators would also have access to an escape-hatch policy that disables the protection when a required enterprise extension overrides the New Tab page or search engine.
The Gerrit changes are still under review, so the feature is not available in stable Chrome yet. Test every layer before attackers do.
Key points
- Google is preparing a new security feature for Chrome that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.
- The feature would protect consumer PCs from malware that abuses enterprise policies to install malicious extensions.
- The proposed protection would block attempts to install policy-controlled extensions that override the New Tab page or default search engine.
- Google is also addressing another trick used by malware, where an extension that you installed manually would no longer be converted into a locked, policy-controlled extension.
If this development plays out positively, it could lead to a significant reduction in malware infections on consumer PCs. This would make the internet a safer place for users and reduce the risk of data breaches.
However, there is a risk that some legitimate administrators may find the new feature to be a hindrance to their work. They may need to use the escape-hatch policy to disable the protection when a required enterprise extension overrides the New Tab page or search engine. This could lead to some confusion and frustration for these users.



