CALIFORNIA, United States — Google Chrome is strengthening its protections against abusive website notifications on Android, introducing multiple layers of automatic controls designed to block deceptive, unwanted and potentially harmful alerts before they reach users.
The browser maker said the measures are part of a multi-year effort involving Chrome Security, Firebase Cloud Messaging (FCM) and Safe Browsing to tackle the growing misuse of web push notifications.
According to Chrome, the protections have already significantly reduced unwanted notifications, with Android users receiving more than 7 billion fewer notifications per day during the first quarter after the measures were introduced.
Rather than relying on a single protection mechanism, Chrome said it has adopted what it calls a “Swiss cheese” model of defence in depth, with multiple safeguards covering different stages of the notification process.
“Our goal is to ensure that if abuse slips through one layer, another is there to catch it,” Chrome said.
Chrome automatically revokes notification permissions
One of the central changes involves automatically removing notification permissions from websites that users have not interacted with for an extended period.
Chrome will also revoke permissions from websites that repeatedly trigger suspicious-notification warnings.
The move is designed to address a common problem in which users grant notification access to a website once and later receive unwanted alerts long after they have stopped visiting it.
Users who still want notifications from a website whose permission has been revoked can review and restore the setting through Chrome’s Safety Hub.
Chrome said the approach is intended to reduce abusive notifications while preserving users’ ability to choose which websites they trust.
Chrome targets networks behind abusive notifications
Google is also using behavioural detection to identify networks of websites that work together to distribute abusive notifications.
The system analyses signals including service-worker activity and coordinated behaviour across multiple websites.
This allows Chrome to identify networks associated with malicious content, scams and other deceptive activity, rather than assessing each website in isolation.
Chrome said permissions can then be proactively revoked from persistent offenders even where an individual website’s content does not initially appear malicious.
“This enables us to proactively revoke permissions from these persistent bad actors, protecting users from deceptive notifications even when the site content might not seem inherently malicious,” the company said.
The approach is particularly relevant to scam networks that can move between domains or operate multiple websites while using similar notification infrastructure.
Abusive websites face notification limits
Chrome is also introducing server-side controls through Firebase Cloud Messaging to restrict websites that generate unusually high volumes of notifications.
The system assesses websites using signals such as:
- Notification volume relative to time spent on the website
- How frequently the site requests notification permission
- Overall user engagement
- Previous notification behaviour
Websites identified as disruptive can be limited to 1,000 messages per minute.
Chrome said websites exceeding the threshold receive HTTP 429 responses, which effectively restricts further notification traffic.
The restrictions become progressively tougher for repeat offenders, with limits reset only after a website demonstrates a sustained period of non-disruptive behaviour.
Android notification prompts get an overhaul
Chrome has also updated the way notification permissions are presented on Android.
The revised permission experience is designed to reduce notification prompt fatigue and give users more control over whether websites can send alerts.
Instead of repeatedly interrupting users with permission requests, Chrome wants people to be able to make more informed decisions about which sites should receive permission to send notifications.
The changes build on Chrome’s earlier introduction of a one-tap unsubscribe feature on Android, which made it easier to withdraw notification permissions from websites sending unwanted alerts.
Google links notification abuse to scams and malware
Chrome said abusive notifications are not merely an annoyance but can form part of broader online attacks.
Malicious actors can use web notifications to direct users towards scams, malware, fraudulent payment requests and attempts to obtain personal information.
Google said its integrated protections are intended to disrupt those attacks by targeting the notification infrastructure used to reach users.
Also Read: Data, privacy, and your period app: Who else knows your secrets?
“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Chrome said.
The controls could also reduce unnecessary background activity associated with unwanted notifications, potentially helping to reduce battery consumption on mobile devices.
How to manage website notifications on Android
Android users do not have to wait for Chrome’s automatic protections to take action. They can manually review website notification permissions through the browser.
On Android, users can open Chrome, tap the three-dot menu, select Settings, then Notifications to review notification preferences.
Users can then decide which notification permissions they want to retain or remove.
On desktop, website notification controls are available through:
Settings → Privacy and security → Site settings → Notifications
Chrome’s combination of automated detection, permission management and server-side restrictions is intended to make web notifications more useful while making it harder for abusive websites and scam networks to exploit the system.
The broader shift reflects Google’s attempt to treat browser notifications not simply as a convenience feature, but as another part of the web’s security and abuse-prevention infrastructure.






