Breaking $89 Million Gone in 41 Minutes: The Coldcard Firmware Exploit That Broke Bitcoin Self-Custody$89 Million Gone in 41 Minutes: The Coldcard Firmware Exploit That Broke Bitcoin Self-Custody$89 Million Gone in 41 Minutes: The Coldcard Firmware Exploit That Broke Bitcoin Self-Custody$89 Million Gone in 41 Minutes: The Coldcard Firmware Exploit That Broke Bitcoin Self-Custody$89 Million Gone in 41 Minutes: The Coldcard Firmware Exploit That Broke Bitcoin Self-Custody
live markets
S&P 5007,489.72▲ 0.70%NASDAQ25,373.85▲ 1.00%DOW52,485.03▲ 0.53%GOLD4,108.00▲ 0.02%WTI CRUDE80.34▼ 5.11%BRENT90.12▲ 0.00%EUR/USD1.1535▲ 0.07%GBP/USD1.3474▼ 0.10%USD/JPY156.36▼ 0.66%NAT GAS2.764▲ 0.62%
pulseofnations.
Mon, Aug 3 2026 — 01:47 UTC telegram ↗ Join the wire

Google Chrome May Block New Tab Hijacker Extensions by Default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine on consumer devices.

Google is developing a new security feature for its Chrome browser that would prevent extensions installed through enterprise policies from hijacking the New Tab page or altering the default search engine on unmanaged consumer devices, according to a report published Saturday by BleepingComputer.

The change targets a long-standing abuse vector in which extensions deployed via IT-administered group policies can persist on personal devices after employees leave an organization. On consumer machines not connected to a corporate domain, these policy-installed extensions currently operate without restrictions, allowing them to override user preferences for the New Tab page and search engine settings.

According to the report, the new feature is being built into the Chromium engine and would automatically block these extensions on devices that are not part of a managed domain. On corporate-managed devices, the extensions would continue to function as intended, preserving IT administrators’ ability to deploy and control browser configurations across their fleets.

The issue has been a persistent headache for Chrome users who have reported unwanted changes to their browsing experience after leaving corporate environments. Extensions that were legitimately installed for work purposes could effectively hijack browser behavior on the same device when used for personal browsing, with no straightforward way for users to override the changes without administrator access.

The feature appears to be part of Google’s broader push to tighten Chrome’s security posture, which has included eliminating manifest v2 extensions, cracking down on deceptive extension listings, and introducing stricter review processes. The company has been increasingly focused on reducing the attack surface of the browser as threat actors exploit extensions as an entry point for malware distribution.

No timeline has been announced for when the feature would ship to the stable channel of Chrome. It is currently in development within the Chromium codebase, and Google may seek feedback from enterprise administrators before finalizing the implementation details.

The move would join a growing list of protections Google has introduced to give consumers more control over their browser experience, while still preserving the flexibility that enterprise IT teams need to manage browsers at scale across large organizations.

Sources: BleepingComputer, IronMonkey Threat Intelligence

Author: Technology Desk

React to this dispatch
Share this dispatch Telegram X WhatsApp

discussion

Join the discussion

Your email address will not be published. Required fields are marked *