
Google is developing a new Chrome security feature that would automatically block extensions from hijacking your New Tab page or changing your default search engine on unmanaged personal computers.
The problem stems from malware abusing Chrome’s enterprise policy system. On properly managed work devices, companies can use enterprise policies to force-install browser extensions and lock certain settings — a legitimate tool for IT departments. But malware has learned to abuse the same system on regular home PCs by writing fake policy keys into your system registry without permission. Chrome then treats the malicious extension as if an administrator installed it, which means you can’t remove or disable it. In some cases, Chrome even displays the confusing “Managed by your organization” message on your personal computer. Under the proposed fix, Chrome will check whether a device is truly managed by a trusted authority (like a company domain or mobile device management system). If it’s not, Chrome will block any extension that tries to override the New Tab page or search engine via these policy tricks. An extension you installed yourself will still work as normal — only policy-forced overrides will be blocked. The Gerrit code changes are still under review, so the feature is not yet available in stable Chrome.
How to check if you’re affected
Affected devices are personal Windows or macOS computers where Chrome displays “Managed by your organization” at the bottom of the Chrome menu — but the PC is not actually owned by a company or enrolled in a mobile device management system. If you see that message on your home computer, a malicious extension may be using fake enterprise policy keys to lock itself in.
To investigate: open chrome://management/ in your browser. If it says “Your browser is managed,” but you don’t work for an organization that manages this PC, type chrome://extensions/ and look for any extension you don’t recognize. On Windows, also check your recently installed programs for software you don’t remember adding — the malware that plants these policy keys usually arrives bundled with other installers.
