Google said Chrome's anti-abuse protections blocked more than 7 billion unwanted web notifications per day on Android in the first quarter of 2026, targeting a channel widely used for scams, phishing, malware delivery, and fraudulent payment requests. The company said its layered defense model combines Chrome Security, Safe Browsing, and Firebase Cloud Messaging (FCM) to detect and disrupt abusive notification activity before it reaches users.
Chrome now automatically revokes notification permissions for inactive sites and for domains repeatedly flagged for suspicious or deceptive behavior, while also analyzing related site networks and coordinated service worker activity to identify persistent bad actors and revoke permissions proactively. Google said it also rate-limits disruptive domains to 1,000 notifications per minute, returning HTTP 429 for excess requests, applies stricter controls to repeat offenders, redesigned Android notification permission prompts to reduce abuse and background activity, and added user-facing controls including Safety Hub review options and one-tap unsubscribe.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Google said Chrome's anti-abuse systems reduced or blocked more than 7 billion unwanted notifications per day on Android during the first quarter of 2026. The company tied the result to its layered defenses against abusive web push notifications.
Google changed Chrome's Android notification permission prompt to a less disruptive design and added simpler user controls, including direct unsubscribe options for unwanted site notifications. Google said the revised approach reduced unnecessary background activity and battery consumption.
Google said sites classified as disruptive are limited to 1,000 notification messages per minute, with excess requests receiving HTTP 429 responses and stricter restrictions for repeat offenders. The controls were presented as a way to reduce large-scale abuse while allowing legitimate notification use to continue.
Google said Chrome now analyzes behavior across related websites, including coordinated service-worker activity, to identify persistent abusive notification actors and proactively revoke their permissions. The detection stack was described as combining Chrome Security, Safe Browsing, and Firebase Cloud Messaging.
Google introduced Chrome protections that automatically revoke notification permissions for inactive websites and for sites identified as abusive or deceptive, with users able to review or restore revoked permissions in Safety Hub. The changes were described as part of Chrome's effort to curb scams, phishing, malware, and other abusive web push notifications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecysecurity.news
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.