{"id":1835,"date":"2026-08-02T23:48:05","date_gmt":"2026-08-02T16:48:05","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-chrome-chong-extension-chiem-new-tab-chinh-sach-doanh-nghiep-bi-lam-dung\/"},"modified":"2026-08-03T03:45:28","modified_gmt":"2026-08-02T20:45:28","slug":"chrome-new-tab-extension-protection-enterprise-policy-abuse","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/hieu-ve-chrome-chong-extension-chiem-new-tab-chinh-sach-doanh-nghiep-bi-lam-dung\/","title":{"rendered":"Understanding Chrome New Tab extension protection: Why enterprise policies can be abused"},"content":{"rendered":"<p><strong>Google Chrome<\/strong> is preparing a new layer of protection to block extensions from being forced by local policy when they try to take over the New Tab page or change the default search engine on unmanaged PCs. This change has not yet appeared in the stable version, but has been noted by BleepingComputer in the series of changes being considered on Chromium Gerrit.<\/p>\n<p>The notable problem is that the browser's legitimate administrative mechanisms can be exploited by malware. In an enterprise environment, administrators can use policies to install required extensions, configure search engines, or block certain options to ensure compliance. But on personal computers, malware can also record local policy keys, making Chrome think that the extension was deployed by an administrator.<\/p>\n<h2>How the mechanism is abused<\/h2>\n<p>When a malicious program has permission to write system configuration, it can add policy keys to Windows or macOS to force Chrome to load an extension. This extension can then change the New Tab page, change the default search engine, or redirect search queries to suspicious websites.<\/p>\n<p>The annoying point is that users often cannot remove or disable extensions in the usual way, because Chrome displays the same status as extensions managed by the organization. In some cases, a notification will also appear <strong>Managed by your organization<\/strong>, even though the actual device does not belong to the enterprise, does not join a domain, and is not managed via MDM.<\/p>\n<p style=\"text-align: center;\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/browser-inline.jpg\" alt=\"Ng\u01b0\u1eddi d\u00f9ng l\u00e0m vi\u1ec7c tr\u00ean tr\u00ecnh duy\u1ec7t web v\u00e0 ki\u1ec3m tra c\u00e0i \u0111\u1eb7t b\u1ea3o m\u1eadt\" style=\"max-width: 100%; height: auto;\" \/><\/p>\n<h2>What Chrome plans to change<\/h2>\n<p>As described in Chromium Gerrit, Google wants to enable a new feature flag by default on unmanaged Windows and macOS devices. This layer of protection will focus on policy-installed extensions that attempt to override New Tab or the default search engine.<\/p>\n<p>If a suitable case is detected, Chrome will cancel the installation process and save the extension ID to the blocked list. The browser will also stop trying to reload the extension during subsequent policy checks, helping to reduce repeated installation requests and limit unnecessary traffic.<\/p>\n<p>Another important change: extensions installed by users themselves will not be turned into extensions blocked by local policies. This helps keep control on the user's end, allowing them to continue disabling or removing the extension if abnormalities are detected.<\/p>\n<h2>Why is this an important signal for common users?<\/h2>\n<p>New Tab and default search engine are two touch points with very high frequency of use. If hijacked, users can be led to fraudulent ads, websites installing spam software, phishing pages or search behavior tracking systems. The level of danger lies not only in the browser changing its interface, but also in the ability to navigate daily access habits.<\/p>\n<p>Chrome's new approach shows that browser developers are making a clearer distinction between enterprise devices with trusted administration and personal machines with only local policies. This is key, because the same technical mechanism may be legal in a centralized administration environment but risky on consumer devices.<\/p>\n<h2>What should users check now?<\/h2>\n<p>Since this feature is still in the review stage, users should not wait for a new update to handle unusual symptoms. If Chrome suddenly changes the New Tab, changes the search engine, displays a message that it is controlled by the organization or does not allow removing an unfamiliar extension, you need to check the extension list, scan for malware and review the browser policy being applied.<\/p>\n<p>For personal devices, notifications <strong>Managed by your organization<\/strong> should be considered a signal that needs to be verified, it is not always a sign of attack but should not be ignored either. Users should prioritize updating Chrome, uninstall software of unknown origin and avoid installing extensions outside the Chrome Web Store if not absolutely necessary.<\/p>\n<h2>Perspective for administrators<\/h2>\n<p>Google still plans to keep an exception policy for legitimate administrators in case a business really needs an extension to override New Tab or a search engine. This helps strike a balance between protecting general users and the need for controlled deployment within the organization.<\/p>\n<p>However, this change also reiterates an important principle: browser policies need to be accompanied by a trusted administrative source. If the organization depends on mandatory extensions, IT teams should ensure devices are managed through a clear domain or MDM, and that communication is transparent so users know the proper management status.<\/p>\n<p>In short, Google's move doesn't just deal with a group of annoying extensions. It reflects the trend of tightening the intersection between legitimate governance and abusive behavior, especially in a context where browsers have become the primary work environment for both individuals and businesses.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> Synthesized from BleepingComputer and Chromium Gerrit<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Google Chrome is preparing to block extensions that abuse local policies to take over New Tab or search settings on personal computers.<\/p>","protected":false},"author":2,"featured_media":1833,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[547,445,440,544,385,86,545,542,543,546],"class_list":["post-1835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-bao-mat-trinh-duyet","tag-browser-security","tag-chrome-extension","tag-chromium-gerrit","tag-google-chrome","tag-malware","tag-managed-by-your-organization","tag-new-tab-hijacker","tag-policy-installed-extension","tag-tien-ich-mo-rong-doc-hai"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1835"}],"version-history":[{"count":1,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1835\/revisions"}],"predecessor-version":[{"id":1836,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1835\/revisions\/1836"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1833"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}