ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Chrome's anti-abuse protections block 7 billion unwanted Android notifications daily

lowPhishing & fraudimportance 42
AI summary · glm-5.3-flash

Google Chrome now auto-revokes web push notification permissions, blocking over 7 billion unwanted and abusive notifications daily on Android.

Google announced anti-abuse measures in Chrome that automatically revoke notification permissions for inactive websites and sites Safe Browsing flags for abusive or deceptive notification practices, with users able to restore permissions via Safety Hub. The protections combine Chrome Security, Firebase Cloud Messaging, and Safe Browsing behavioral detection of coordinated abusive networks, and blocked more than 7 billion unwanted notifications per day on Android in Q1. Google also limits abusive domains to 1,000 push messages per minute via FCM and redesigned Android prompts with one-tap unsubscribe.

  • Chrome revokes notification permissions for inactive or abusive sites identified via Safe Browsing.
  • Behavioral detection of service worker activity targets coordinated abusive notification networks.
  • FCM rate limits abusive domains to 1,000 push messages per minute with HTTP 429 for violators.
  • Protections blocked over 7 billion unwanted notifications daily on Android in Q1; one-tap unsubscribe added.
Full article322 words · extracted from helpnetsecurity.com · click to collapse

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content.

Chrome push notification permission controls

Abusive notifications (Source: Google)

Chrome revokes notification permissions for websites users have not recently interacted with and for sites that Google Safe Browsing identifies as engaging in abusive or deceptive notification practices. Users can review and restore revoked permissions at any time through Chrome’s Safety Hub if they trust the website.

The company’s multi-layered approach combines Chrome Security, Firebase Cloud Messaging (FCM), and Safe Browsing to detect and block abuse throughout the notification lifecycle.

According to Google, these protections blocked more than 7 billion unwanted notifications per day on Android during the first quarter of the year.

Behavioral detection of abusive networks

To identify and remove permissions from networks of websites that coordinate abusive notifications, the company developed behavioral detection that analyzes service worker activity to identify networks distributing malware, scams, and other malicious content.

“This enables us to proactively revoke permissions from these persistent bad actors, protecting users from deceptive notifications even when the site content might not seem inherently malicious,” Hannah Buonomo of Chrome Security, Jonathan Li of Safe Browsing, and Nidhi Davawala of Firebase Cloud Messaging at Google, said.

Improving notification permissions

Google limits abusive websites to 1,000 push messages per minute through Firebase Cloud Messaging (FCM). Domains that exceed the threshold receive HTTP 429 responses, while repeat offenders are subject to stricter rate limits until they demonstrate sustained non-disruptive behavior. This approach helps reduce large-scale notification abuse while allowing legitimate websites to continue using push notifications.

The company has updated Chrome’s permission model to give users greater control over browser alerts. The latest changes include a redesigned Android permission prompt that reduces interruptions and helps users make informed decisions. A one-tap unsubscribe feature also lets users quickly revoke notification permissions from websites that send unwanted or excessive alerts.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/12/google-chrome-abusive-web-push-notifications/