Google removes Chrome admin privileges to reduce threat posed by dodgy extensions
- A Microsoft dev has submitted an update to Chromium
- The update de-elevates Chrome, to run without admin privileges by default
- This should prevent malicious add-ons and extensions from operating freely
Future versions of Chrome on Windows will most likely not run with admin privileges by default. That way, users should be better protected from suspicious extensions, risky websites, and other potentially malicious activities.
Earlier in May, a Principal Software Engineer at Microsoft, Stefan Smolen, submitted a commit to the Chromium source code, with which Chrome will automatically de-elevate when users try to launch it with elevated permissions.
“This CL is based on changes we’ve had in Edge, circa 2019, which attempts to automatically de-elevate the browser when it’s run with the elevated part of a split / linked token,” Smolen said in the commit. “This automatically attempts a relaunch once, and then if it still fails it falls back to the current behaviour (which tries to launch admin).”
Securing Chrome
The feature has been present in Edge since 2019. When users launch Edge with elevated permissions, the browser would display a warning and a recommendation to relaunch it without admin privileges.
“We append a command-line switch to prevent auto-relaunch if, for whatever reason, we re-launch into admin mode again,” the commit further reads. “We do not de-elevate Chrome when it’s running in automation mode so we don’t interfere with automation tools.” This feature also prevents potential infinite loops.
Being a window to the wider internet, the web browser is one of the most frequently targeted programs. It constantly handles untrusted data from countless sources, which is why cybercriminals are always looking for vulnerabilities – either in the code, in plugins, or in poorly secured websites. Compromising a browser can give threat actors access to sensitive information including login credentials, personal data, and more.
By taking away admin privileges from the browser, Microsoft disarms it, preventing threat actors from running malware or stealing personally identifiable information. Therefore, the Redmond giant advises all users not to launch their browsers with admin rights.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
You might also like
A Microsoft dev has submitted an update to Chromium The update de-elevates Chrome, to run without admin privileges by default This should prevent malicious add-ons and extensions from operating freely Future versions of Chrome on Windows will most likely not run with admin privileges by default. That way, users should…
Recent Posts
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023