Google is rolling out a new defense for Chrome extensionsto protect the new tab from installations that arbitrarily change the default search engine. The protection is still in development, but it targets a practice that can turn a personal computer into a persistent redirect environment.

The change was spotted in a Chromium code review and has not yet been enabled in the stable version of Chrome. According to a report by BleepingComputer, the design primarily affects unmanaged Windows and macOS devices, where local settings can display an extension as supposedly approved by an administrator.
See also: Vulnerability in Adobe Acrobat extension for Chrome exposes WhatsApp conversations
Chrome New Tab and Extensions
The problem begins when a malicious program adds local policy keys without the user's explicit consent. This can force an extension to replace the new tab page, modify the search engine, or redirect queries to suspicious websites.
The current behavior is particularly misleading. The new tab page may change without clear notification, and the user's search may be redirected to a service they did not choose. Chrome may assume that the installation is from an organization and prevent the extension from being disabled or removed. In some cases, the message "Managed by your organization" appears even though the computer is personal and not connected to a corporate domain or MDM system.
Google describes personal systems as low-trust environments because the browser reads local policies without confirmation from a trusted authority. The issue does not apply to normally managed devices in an enterprise, where policies come from a domain or centrally managed platform.
The distinction between authoritative management and local enforcement is critical for security. A company may need an internal homepage or a dedicated search engine, but these options must be implemented by a controlled infrastructure and accompanied by clear employee communication.
On a personal computer, however, the same technique can be used for browsing tracking, advertising redirects, or search data collection. Canceling the installation before it takes effect is a more effective defense than trying to remove a locked extension after installation.

How Chrome's new protection will work
The mechanism under development is tied to the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices. When enabled, Chrome will cancel the installation of policy-enforced extensions that attempt to change the new tab or search on unmanaged devices.
The browser will store the ID of the blocked extension and will not unnecessarily re-download it on subsequent policy checks. At the same time, a manually installed extension will not be able to be later turned into a locked installation only through local settings. The user will retain control to disable or remove it.
The protection also provides a special exception for legitimate corporate installations. An administrator can disable the feature when a necessary work extension really needs to replace the new tab or default search. If a previously managed device loses its trusted management, the relevant extensions can be automatically removed.
See also: Bug in Claude for Chrome allowed extensions to read Gmail

What the change means for users
The feature is not yet available for immediate enablement in the stable release, and the changes to Chromium are still under review. For Chrome extensions, the final behavior may change before release, depending on test results and the needs of managed organizations. Adding metrics will help Google track how often such attempts occur and how many installations are actually blocked.
Until the rollout is complete, users should be wary of unexpected changes to Chrome's search engine, new tab, or admin indicator. The SecNews technical team recommends checking installed extensions, removing unknown programs, and confirming that a corporate policy is indeed coming from the organization.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Chrome extensions remain useful when installed from a trusted source and only request necessary permissions. However, the new tab and search engine are high-value settings because they affect every session and can direct the user to misleading pages.
See also: Malicious Chrome extension hijacks address bar searches

