Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026.
The company says notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests.
Rather than relying on one protection, Google says Chrome uses a "Swiss cheese" defense model, where several overlapping systems try to stop abuse at different stages.
"Our goal is to ensure that if abuse slips through one layer, another is there to catch it," Google explained in a blog post.
Chrome can automatically revoke notification permissions
Chrome already removes notification permissions from websites users have not interacted with recently, as well as sites that repeatedly trigger suspicious-notification warnings.
Google is also analyzing behavior across networks of related websites, including coordinated service-worker activity, to identify groups distributing malicious or deceptive notifications.
"This enables us to proactively revoke permissions from these persistent bad actors, protecting users from deceptive notifications even when the site content might not seem inherently malicious," Google said.
Google evaluates factors such as notification volume, time users spend on a site, permission-prompt frequency, and engagement.
According to the company, sites classified as disruptive can be limited to 1,000 messages per minute, with excess requests returning an HTTP 429 error.
"This strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable," the company noted.
Chrome users can review notification permissions under Settings > Privacy and security > Site Settings > Notifications on desktop, or Settings > Notifications on Android.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report
Post a Comment Community Rules
You need to login in order to post a comment
Not a member yet? Register Now
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.