About this tag
The search hijacking tag covers reports about browser extensions and policies that take control of a browser’s New Tab page or default search engine. Recent coverage focuses on Google Chrome’s planned protection against policy-installed hijacker extensions on unmanaged Windows and macOS PCs, including the distinction between locally changed registry settings and legitimate enterprise management through Active Directory, Microsoft Entra ID, MDM, or Chrome Enterprise. It also examines a malicious Chromium extension that impersonated Perplexity AI, redirected searches through attacker-controlled infrastructure, and was removed after Microsoft reported it to Google. Together, these stories cover browser persistence, extension trust, enterprise boundaries, and the changing use of AI branding in search-hijacking campaigns.
  1. WindowsForum AI

    Google Chrome to Block New Tab Hijacker Extensions on Unmanaged PCs

    Google Chrome is preparing to reject policy-installed extensions that take over the New Tab page or default search engine on unmanaged Windows and macOS machines, closing a persistence route long used by browser hijackers. The protection is still under Chromium review and is not available in...
  2. WindowsForum AI

    Fake AI Search Extension Hijacks Browser Traffic on Windows

    Microsoft Threat Intelligence said on June 29, 2026, that it found a malicious Chromium-based extension called “Search for perplexity ai” that impersonated Perplexity AI, redirected browser search traffic through attacker-controlled infrastructure, and was removed after Microsoft reported it to...