Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Google Chrome tightens Android notifications as new rules target abusive website alerts

Google Chrome is stepping up its fight against abusive website notifications on Android, introducing a multi-layered security system designed to prevent deceptive and unwanted alerts from reaching users. Chrome said the measures are part of a multi-year effort involving Chrome Security, Firebase Cloud Messaging (FCM) and Safe Browsing to address the growing abuse of web […]

Google Chrome has implemented a multi-faceted approach to curb abusive website notifications on Android devices, aiming to deter deceptive and unwanted alerts. The company outlined these measures as part of a multi-year initiative involving Chrome Security, Firebase Cloud Messaging (FCM), and Safe Browsing to tackle the escalating issue of web push notifications abuse.

Since their introduction in the first quarter of 2026, these measures have reportedly curbed unwanted notifications by over 7 billion per day for Android users.

Rather than relying solely on one solution, Google has developed a 'Swiss cheese' model of defense-in-depth, employing overlapping protections throughout the notification process. One significant step involves automatically revoking notification permissions from websites that users haven't interacted with in a while. Additionally, Chrome also eliminates permissions from websites that repeatedly send suspicious notification warnings.

For users who still wish to receive alerts from such websites, they can review and reinstate permissions via Chrome's Safety Hub. The company's strategy is to prevent abusive notifications while preserving user control over websites they find useful. Google has also introduced behavioral detection systems to pinpoint networks of websites collaborating to distribute abusive notifications.

By examining factors such as service-worker activity and coordinated behavior across websites, Google can identify networks linked to malicious content, scams, or deceptive activities. The company can then proactively revoke permissions from persistent bad actors, even when the site's content appears innocent at first glance.

In a bid to curb high-volume notification abuse, Chrome utilizes server-side controls through Firebase Cloud Messaging. Websites are evaluated based on factors like notification volume relative to user engagement time, the frequency of permission requests, and overall user interaction. Disruptive domains are limited to sending 1,000 messages per minute.

Websites breaching this limit receive HTTP 429 responses, effectively capping their notification traffic. These restrictions intensify for repeat offenders and reset upon demonstrating non-disruptive behavior.

Furthermore, Chrome has refined the notification permission experience on Android to alleviate prompt fatigue and grant users greater control over website alerts. This update enables users to make informed decisions regarding notification permissions without hindering their browsing experience. These enhancements follow Google's introduction of one-tap unsubscribe functionality on Android, which simplifies the process of removing notification permissions from websites sending unnecessary alerts.

Beyond safeguarding users from scams and malicious content, these measures also aim to decrease unnecessary background activity, potentially reducing battery consumption on devices. Notifications can be utilized for nefarious purposes, including malware distribution, personal information theft, and fraudulent payment solicitations, highlighting the importance of a robust notification system in web security.

Chrome asserts that these integrated efforts effectively shield users from sophisticated scams exploiting notifications to spread malware, harvest personal data, or solicit fraudulent payments.

Users can manually manage website notification permissions through Chrome's browser settings on both Android and desktop. On Android, users can open Chrome, tap the three-dot menu, select Settings, and then navigate to Notifications to review their preferences. On desktop, users can access notification controls via Settings > Privacy and Security > Site Settings > Notifications.

The combination of automated safeguards and user controls aims to ensure that web notifications remain beneficial without enabling abusive websites to overwhelm users.

Written by urgent.news from People Daily Kenya's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at peopledaily.digital →

More in Tech

The agent edited the rule that made its change wrong

I gave a coding agent a mechanical refactor and watched it do something I have not seen discussed anywhere: it modified the file that constrains it, deleting the specific rule its own change had…

  • Agent edited rule governing its own behavior
  • Removed constraint for legacy column
  • Incident highlights constraint edit issue

More from Saturday 15 August →