Google Chrome’s New Defense Model to Protect Users Against Malicious Notifications


According to Google, Chrome’s anti-abuse system has decreased unwanted notifications in the first quarter of 2026 by over 7 billion daily on Android.

In a new blog post, Google said that notification exploits have been used to spread malware, scams, fake payment requests, and phishing attempts.

To decrease the exploit, Google made a “Swiss cheese” defense system, where numerous overlapping systems simultaneously try to stop exploit at different levels.

According to Google, "Our goal is to ensure that if abuse slips through one layer, another is there to catch it. This approach allows us to halt abuse at the source, preventing deceptive content from reaching users while maintaining a healthy balance between utility and security."

Automatic notification permission removal by Chrome

Currently, Chrome can already revoke notification permissions from inactive sites, and also from websites that continuously give suspicious-notification warnings.

This can automatically unsubscribe a user from a website’s notification if Chrome removes the permission.

According to Google, users can still see the automatically revoked permissions in Safety Hub and permit access again if they wish to.

Users can also unsubscribe from notifications directly from the notifications panel of Android.

Besides allowing users more control, Google is studying user behaviour throughout networks of associated websites. This includes coordinated service-worker activity, to look out for groups spreading harmful or malicious notifications. 

According to Google, "This enables us to proactively revoke permissions from these persistent bad actors, protecting users from deceptive notifications even when the site content might not seem inherently malicious."

Google analyzes factors including time you spend on a website, engagement, permission-prompt frequency, and notification volume. 

For instance, websites categorized as malicious can be restricted to 1,000 messages per minute, with additional requests showing an HTTP 429 error. These restrictions are reset after a period of non-disruptive behaviour and can be more strict for repeat violators, Google said.

Users can also control notification settings

Chrome has also modified how notification permissions prompts function on Android. Chrome has built a relatively less disruptive interface for users to decide if they want certain notification without poking their browsing. 

"This strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable," Google said.

How to turn on settings

For users who want to manually control these settings, for Chrome users, “On Desktop, navigate to Settings > Privacy and security > Site Settings > Notifications, or open chrome://settings/content/notifications in the omnibox,” Google said.

For android, “tap More (⋮) > Settings > Notifications.”

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: