Google says Chrome’s anti-abuse systems blocked more than 7 billion unwanted notifications on Android each day during the first quarter of 2026. The browser is targeting a growing source of scams, phishing attempts, malware delivery and fraudulent payment requests.
Notification abuse has become a major threat
Website notifications can be useful for news alerts, order updates and messages. However, cybercriminals increasingly use them to send deceptive pop-ups directly to users’ devices.
These alerts can impersonate antivirus warnings, package-delivery updates, banking messages or prize offers. They may then direct users to phishing pages, malicious downloads or payment scams.
Google says its response uses a multi-layered approach. Rather than relying on one detection system, Chrome notifications are reviewed by several overlapping defences designed to catch abuse at different stages.
This model aims to stop harmful campaigns before they reach users. If one layer misses suspicious activity, another can identify and block it.
Chrome can revoke site notification permissions
Chrome already removes notification permissions from websites that users no longer visit. It can also revoke access from sites that repeatedly trigger suspicious-notification warnings.
When the browser removes permission, it can automatically unsubscribe the user from future Chrome notifications from that site. Users can still review revoked permissions in Chrome’s Safety Hub and allow notifications again if they choose.
Android users can also unsubscribe directly from the notifications panel. This makes it easier to remove unwanted alerts without returning to the website that sent them.
Google has also changed how notification permission prompts appear on Android. The redesigned prompts are less disruptive, giving users more control without interrupting their browsing as aggressively.
Google tracks coordinated abusive sites
Google does not only assess notifications from individual websites. Its systems also look for patterns across networks of related sites.
For example, Chrome can analyse coordinated service-worker activity to identify groups of websites that distribute deceptive notifications. This allows the browser to revoke permissions from persistent offenders, even when a particular website does not appear obviously malicious at first glance.
Google considers several signals when identifying abusive activity. These include notification volume, how long users remain on a site, how often it requests permission and whether users meaningfully engage with its content.
Sites that Chrome classifies as disruptive can face delivery limits. Google says these sites may be restricted to 1,000 notification requests per minute, while additional requests receive an HTTP 429 error.
Repeat offenders can face stricter restrictions. The limits are only reset after a period of non-disruptive behaviour.
Users can review Chrome notifications settings
Google says the changes have reduced unnecessary background activity and helped lower battery consumption on Android devices. The company also says users should now receive more relevant notifications while unwanted alerts are blocked earlier.
Desktop Chrome users can review site notification permissions under Settings, then Privacy and security, Site Settings and Notifications.
On Android, users can review Chrome notifications through Settings and Notifications. Removing permissions from unfamiliar or unnecessary websites remains one of the simplest ways to reduce scam and phishing risks.


0 responses to “Chrome blocks 7 billion unwanted Android notifications every day”