Google Chrome to Block New Tab Hijacker Extensions by Default
What Happened – Google disclosed a forthcoming Chrome feature that will, by default, block policy‑installed extensions that attempt to hijack the New Tab page or change the default search engine on unmanaged Windows and macOS devices. The change targets “low‑trust” consumer PCs where malware can silently add local Chrome policy keys and force‑install malicious extensions.
Why It Matters for Compliance & Audit Readiness
- The scenario exemplifies a control‑gap in access‑control and change‑management that SOC 2 audits require organizations to monitor (CC6.1 System Operations, CC7.1 Change Management).
- Continuous evidence of policy enforcement and remediation (e.g., blocked‑extension logs) can serve as audit‑ready artifacts.
- Demonstrating that your browser‑policy controls are hardened aligns with the Control Mapping capability, providing verifiable proof that you meet SOC 2 trust‑service criteria.
Who Is Affected – All enterprises that rely on Chrome for employee browsers, especially those with mixed managed/unmanaged device fleets (tech SaaS, finance, healthcare, education, etc.).
Recommended Actions
- Review your Chrome enterprise policy configuration and ensure extensions are only force‑installed on devices enrolled in a trusted MDM or domain.
- Map the upcoming “kBlockDseNtpOverrideExtensionsOnUnmanagedDevices” flag to your SOC 2 control matrix (CC6.1, CC7.1) and begin collecting the generated block‑extension logs as continuous compliance evidence.
- Update your security awareness training to cover the risk of unauthorized policy keys and how users can identify the “Managed by your organization” UI cue on consumer PCs.
Source: BleepingComputer
Technical Notes – The protection works by canceling the installation of policy‑controlled extensions that override the New Tab page or default search engine, persisting the blocked extension ID, and automatically uninstalling affected extensions if a device loses trusted management status. No CVE is associated; the change mitigates a policy‑misconfiguration abuse vector.