Chrome blocks malware hijacking the new tab page

Google Chrome blocks malware from hijacking the New Tab page and search engines on personal computers using a new security update currently in testing. The feature targets a specific type of attack where malicious software exploits enterprise policy mechanisms to gain control over browser settings. Organizations use these same tools to manage work computers, but attackers are finding ways to weaponize them on consumer hardware. This vulnerability allows bad actors to replace the default homepage with a malicious search provider or inject unwanted content into the browser’s opening tab.
How Malware Uses Enterprise Policies
Chrome allows organizations to force-install extensions and manage settings on devices connected to a domain or mobile device management system. Malware can exploit the same feature on unmanaged consumer PCs. It adds local policy keys without user consent. This forces extensions to replace the New Tab page or change the default search engine. Chrome treats these as administrator-installed, preventing users from removing them. The browser displays a “Managed by your organization” message even on devices that are not managed by any organization.
Related: FF14 Heads to Nintendo Switch 2
The New Blocking Feature
Google refers to consumer PCs as “low-trust” environments because Chrome reads locally stored policies without verification from a trusted authority. In low-trust environments (unmanaged consumer devices), enterprise policy force-installs and recommendations are abused to lock in search engine or new tab page hijackers, Google’s Anunoy Ghosh wrote in a post. This distinction highlights how the browser lacks a mechanism to distinguish between a genuine corporate requirement and malicious software on personal hardware.
Google is rolling out an update that enables the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices feature flag by default. This activates an end-to-end defense for unmanaged Windows and macOS machines. When Chrome detects a policy-controlled attempt to override the New Tab page or default search engine, the installation will be canceled. The extension ID gets recorded in a blocked list. Future attempts to download the same extension are stopped.
Google is also addressing a related issue where extensions installed manually by users will no longer be converted into locked, policy-controlled extensions. This ensures users retain the ability to disable or remove them. If a previously managed device loses its trusted management status but retains local policy keys, Chrome will automatically uninstall affected New Tab and search engine override extensions.
Related: Computer Helped Win World War II
Protecting Enterprise Needs
Legitimate administrators will retain access to an escape-hatch policy. This allows them to disable the protection if a required enterprise extension needs to override the New Tab page or search engine. Google is also implementing metrics to track the frequency of policy-based hijackers and how often Chrome blocks them. The company plans to enable the protection by default on unmanaged Windows and macOS devices once approved. It has not announced a target Chrome version or release date.
Troubleshooting and Diagnosis
Users who suspect a hijacker on a personal device should follow a specific diagnostic process. They can type “policy” in the address bar to see whether unexpected policies are set on an unmanaged personal device. It is also wise to investigate any extension marked as installed by an administrator or accompanied by a message on a PC that is not managed by an organization. A reputable anti-malware scan is recommended, as malicious local policy keys are typically added by a separate program on the system. Finally, removing the local policy keys and any associated malware is necessary, as deleting the extension alone may not prevent reinstallation if the policy remains.

FF14 Heads to Nintendo Switch 2
