Google Chrome to block policy‑installed New Tab hijackers on unmanaged PCs
Google is adding a new Chrome feature, kBlockDseNtpOverrideExtensionsOnUnmanagedDevices, that will be enabled by default once approved. The feature stops the installation of extensions that use enterprise policies to override the New Tab page or default search engine on devices that are not managed by an organization. When such an extension is detected, Chrome cancels the install, records the extension’s ID in a block list, and prevents it from being re‑downloaded in subsequent policy checks. If a device loses its trusted management status, Chrome will automatically remove the offending extensions while preserving user‑installed ones. An escape‑hatch policy allows legitimate enterprise extensions to function when needed. Administrators can monitor suspicious extension activity through Chrome extension telemetry, available to Google Workspace customers with Google Security Operations. The change targets low‑trust consumer environments where malware can set local Chrome policy keys without a domain or mobile‑device‑management system. The feature is not yet in the stable Chrome release.
Entities: Chrome · Google · Google Workspace