
Google is always looking for new ways to beef up security in Chrome and anything else it offers, and now that will include new extension securities to thwart efforts by hackers to hijack new tab pages. These new securities will also prevent changing the default search engine. The issue really lies mainly with personal devices that can be targeted for attack using policy-forced extension installs to gain control of certain functions.
A whole host of problems could arise from this if left unchecked. For instance, a hijacker could use the enterprise policy to force-install an extension into your Chrome browser and from there, use the changed default search engine to redirect searches to whatever site the hijacker wishes. To make matters worse, because the forced installation used an enterprise-level policy, Chrome could end up thinking your own personal PC is owned by an organization with the extension having been installed by an admin, and then you end up not having the permission to remove the extension.
Google hasn’t rolled this extension security out to a stable Chrome build just yet
According to a report from The Bleeping Computer, Google is working on this security feature addition but it hasn’t rolled things out yet. Once things are ready to go and Google feels things are a stable enough position to be pushed out, the security changes will be enabled by default. Meaning you won’t have to hunt the security feature down and turn it on yourself.
In addition, Google is making it so that manually-installed extensions can’t be changed into extensions that are controlled by organization admin policies. This allows the user who initiated the installation to still have control over the extension and whether or not it can remain installed. As of right now there are no confirmed dates for the release of this feature.
The post Google’s new Chrome security feature prevents extensions from abusing control appeared first on Android Headlines.
​Â