Google says Chrome blocked seven billion malicious Android notifications every day in its bid to cut down on scams | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
Google says Chrome blocked seven billion malicious Android notifications every day in its bid to cut down on scams
"Swiss cheese" approach to defense seems to be working
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Google cut seven billion daily Android Chrome notifications using layered defenses
Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam
Android improvements simplify managing alerts and reduce scam and malware exposure
Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day.
In a new report, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer.
Most importantly, Google says the achievement significantly improved the overall user experience on Android.
For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them.
When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.
How scammers use "scraped New York Times content" to trick security scanners
Android users beware — this huge fraud scam campaign hit millions of victims around the world
Hackers could use poisoned Whats App and Slack notifications to take over your Google Gemini – and make it work on their behalf
Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from Whats App, Gmail, or other apps).
Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here.
Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content.
Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk.
But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.
New 'scareware' attack hits 2.8 million victims, pretending to lock them out of your browser
Experts warn hackers are hiding malware inside Google's own ad systems — here's what we know
Digital spring cleaning is now a frontline defense in the scam economy
Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while.
So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.
The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them.
On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.
In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.
Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings.
“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said.
“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”
➡️ Read our full guide to the best antivirus
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with Life Lock
- Best for mobile: Mc Afee Mobile Security
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Sorry, Apple and Samsung — I test smartwatches for a living, and the Google Pixel Watch 5 specs beat the Series 11 and Galaxy Watch 9 in these five key areas
7 things we saw at the Pixel 11 launch — from Google’s new illuminated phones and to the Pixel Tag
I spent a couple of hours with the new Google Pixel 11 Pro Fold — it’s not a reinvention, but a nudge toward perfection
The Pixel Tag is here — but it won't be an Air Tag for Android until Google fixes these Find Hub issues
I’ve used the new Pixel 11, Pixel 11 Pro, and Pixel 11 Pro XL, and Google's made nearly all the improvements I wanted to see — and the 'Hi Light' feature is the surprising standout
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



