420/69 Tuesday, August 4, 2026

Google is preparing to add a new security feature in Chrome to block extensions that attempt to change the New Tab page or default search engine through enterprise policies on unmanaged Windows and macOS devices. The feature aims to reduce attacks involving browser hijacker extensions, which may redirect users to unwanted websites or search engines.
Reports indicate that Chrome normally allows organizations to use enterprise policies to install extensions or configure certain browser settings. However, some malware families abuse this mechanism by adding policy keys to regular users’ devices to force the installation of extensions that change the New Tab page, modify the default search engine, or redirect search results to suspicious websites. This can cause Chrome to display a “Managed by your organization” status even when the device is not managed by an organization, and users may be unable to remove or disable the extensions through normal methods.
Under the new protection, Chrome will block policy-controlled extension installation if the extension attempts to change the New Tab page or default search engine on devices that are not managed by an organization. Chrome will also store the extension ID of the blocked extension to prevent the browser from repeatedly trying to download the same extension during the next policy check. In addition, extensions installed by users themselves will not be converted into policy-locked extensions. The feature is still under development and had not yet been enabled in Chrome Stable at the time of reporting. Users should review installed extensions, remove unknown extensions, and check for anomalies if they see the “Managed by your organization” message on a personal device.
