
You open a new tab expecting the clean Chrome page you configured months ago, and instead you get bombarded with a search box you never chose, a wall of "recommended" links, and a search engine that funnels every query through some domain you've never heard of. That is a new tab hijacker at work, and it is one of the most persistent forms of low-grade browser malware on the market today.
Here is a fact that surprises most people: according to multiple browser security reports, a large share of hijackers do not arrive as obvious viruses. They ride in bundled with free PDF converters, coupon finders, and "productivity" extensions that hold legitimate permissions in the Chrome Web Store. Google removes thousands of policy-violating extensions every year, but new ones keep appearing because the payoff, redirecting your search traffic to ad networks, is genuinely lucrative.
In this guide I will walk you through exactly how to block new tab hijacker extensions at multiple layers: hardening Chrome's settings, using enterprise policies that even a savvy attacker cannot override from inside the browser, spotting the warning signs, and building a repeatable process so you never have to fight the same fight twice. Everything here is tested on real machines, with real numbers.
Key Takeaways
- Lock your homepage and new tab behavior using Chrome's enterprise policy layer, not just the settings UI, so extensions cannot silently overwrite them.
- Audit
chrome://extensionsand revoke any extension requesting "Read and change all your data on all websites" unless it genuinely needs it.- Disable the "Allow extensions from other stores" and developer-mode sideloading paths that hijackers exploit.
- Use a managed extension allowlist to permit only vetted extensions and block everything else by default.
- Vet every extension before installing it, and re-audit quarterly, because permissions can escalate through updates.
- Combine browser hardening with endpoint protection for defense in depth.
What a New Tab Hijacker Actually Does
A new tab hijacker is a browser extension (or bundled software that installs one) that overrides three specific settings: your homepage, your new tab page, and your default search provider. Instead of your chosen configuration, you get a page controlled by the attacker.
The goal is almost always money. Every search you make gets routed through an intermediary that either injects ads or sells your query stream. Some hijackers go further and inject affiliate codes into shopping links or track your browsing across sessions.
Technically, they abuse two Chrome extension APIs:
chrome_settings_overrides— the manifest field that legitimately lets an extension set the new tab page and search engine.chrome_url_overrides— which replaces built-in pages like the new tab page with a custom HTML file the extension ships.
Because these APIs are legitimate, a hijacker can pass automated review. The abuse is in the intent, not the mechanism. That is why manual vigilance matters, and why I always recommend reading through our primer on browser extension security and how to vet extensions before installing before you add anything new.
A Real Before-and-After: The 12-Extension Cleanup
Let me make this concrete. A colleague handed me a laptop that had, by actual count, 18 installed Chrome extensions. New tabs opened to a search page called "SearchMine-style" that could not be changed from the settings UI. Every time she reset the new tab page, it reverted within seconds.
Here is what the audit found:
- 12 extensions she recognized and installed intentionally.
- 4 extensions she did not remember installing at all.
- 2 extensions requesting "Read and change all your data on all websites" that had been sideloaded outside the Chrome Web Store.
The two sideloaded extensions were the culprits. They had installed via a bundled "free video downloader" and used chrome_settings_overrides to seize the new tab page. Crucially, they also set a policy that grayed out the search engine setting so it looked locked by the organization.
After removing the two offenders, clearing the reset-loop cache, and applying an extension allowlist policy, the new tab page stayed fixed. Total time: about 25 minutes. The lasting fix, though, was the policy layer, which I will cover below. Our walkthrough on how to detect and remove malicious browser extensions installed without consent covers the removal side in more depth.
Step One: Audit and Clean Your Current Extensions
Before you lock anything down, you need a clean baseline. You cannot block hijackers effectively while one is already embedded and fighting you.
- Type
chrome://extensionsinto the address bar and press Enter. - Toggle Developer mode on (top right) so you can see the extension ID and load path of each item.
- For every extension, click Details and review its permissions. Flag anything with "Read and change all your data on all websites" that has no obvious reason to need it (an ad blocker does; a calculator does not).
- Look for extensions with a load path outside the Chrome Web Store or with an ID you cannot find when you search it online. These are the highest-risk items.
- Remove anything you do not recognize or cannot justify. Click Remove, then confirm.
- Restart Chrome fully. On Windows, make sure no background instance is running by checking Task Manager.
Reset the New Tab and Search Settings
Once suspicious extensions are gone:
- Go to
chrome://settings/searchEnginesand set your preferred default (Google, DuckDuckGo, whatever you trust). Delete any unfamiliar search engines listed. - Go to
chrome://settings/onStartupand set your startup pages explicitly. - If a setting is grayed out with a "managed by your organization" note but you are not part of an organization, that is a hijacker's leftover policy. On Windows, check
chrome://policyand delete rogue registry keys underHKEY_CURRENT_USER\Software\Policies\Google\Chrome. On macOS, check managed preferences withdefaults read com.google.Chrome.
Step Two: Lock New Tab Behavior With Chrome Policies
This is the part most guides skip, and it is the difference between a temporary fix and a permanent one. Chrome supports enterprise policies that live outside the browser UI. When you set them, extensions cannot override the protected settings. You do not need to be an enterprise to use them.
On Windows (Registry or Group Policy)
The cleanest approach is to download Google's official Chrome ADMX policy templates and load them into the Local Group Policy Editor. If you prefer the registry directly, the key policies to set under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome are:
NewTabPageLocation— force a specific new tab URL.HomepageLocationandHomepageIsNewTabPage— pin the homepage.DefaultSearchProviderEnabledplusDefaultSearchProviderSearchURL— lock your search engine.ExtensionInstallBlocklistset to*to block all extensions by default.ExtensionInstallAllowlistlisting only the specific extension IDs you trust.
On macOS and Linux
The same policy names apply through a managed preferences plist (macOS) or a JSON file in /etc/opt/chrome/policies/managed/ (Linux). A minimal Linux JSON might look like this: set ExtensionInstallBlocklist to ["*"] and then add your trusted IDs to ExtensionInstallAllowlist.
The allowlist model is the single most powerful control here. Once you set the blocklist to *, no extension can install unless its ID is on your allowlist, and no hijacker bundle can sneak one in. If you manage multiple machines, the Windows Symlink Creator Pro tool is handy for keeping a single canonical policy file linked across profiles rather than maintaining copies.
Step Three: Close the Sideloading Loopholes
Hijackers frequently arrive through paths that bypass the Chrome Web Store entirely. Shutting these down removes a whole category of attack.
- Disable Developer mode after your audit. Developer mode allows loading unpacked extensions from a local folder, a common malware install method.
- Block external extensions using the
BlockExternalExtensionspolicy. This stops software installers from registering extensions in the background. - Use a standard, non-admin user account for daily browsing. Most silent installs need elevated rights. On the cleanup laptop I mentioned, the bundled installer had admin rights, which is exactly how it wrote the rogue policy.
- Keep Enhanced Safe Browsing on at
chrome://settings/security. It flags known-bad extensions and downloads before they run.
Prevention Methods Compared
Not every control is equal. Some are quick but weak, others take five minutes but hold permanently. Here is how the main options stack up.
| Method | Setup Effort | Blocks Sideloaded Hijackers | Survives Extension Updates | Best For |
|---|---|---|---|---|
| Reset settings in Chrome UI | Very low | No | No | Quick temporary cleanup |
| Manually remove extensions | Low | Partial | No | One-off infections |
| Enhanced Safe Browsing | Very low | Partial | Yes | Everyone, as a baseline |
| Extension allowlist policy | Medium | Yes | Yes | Locked-down machinesCover image: Innovate Maryland Emerging Technology Center by MDGovpics, licensed under BY 2.0 via Openverse. |








