Google Chrome Blocks 7 Billion Abusive Android Notifications Daily
Google Chrome's enhanced anti-abuse measures automatically revoke notification permissions for inactive or suspicious websites, blocking billions of unwanted alerts daily.

Google Chrome has implemented significant new anti-abuse protections on its Android platform, automatically revoking notification permissions for websites that are either inactive or flagged by Google Safe Browsing for deceptive practices. This proactive approach aims to curb the spread of scams, phishing attempts, and other malicious content delivered through web push notifications.
These enhanced measures are part of a multi-layered strategy that integrates Chrome Security, Firebase Cloud Messaging (FCM), and Safe Browsing. The system is designed to detect and block abuse across the entire notification lifecycle. During the first quarter of 2026, these protections were instrumental in blocking an estimated 7 billion unwanted notifications per day on Android devices.
A key component of this new defense is behavioral detection, which analyzes service worker activity to identify coordinated networks of websites distributing malware, scams, or other malicious content. By focusing on the behavior of these networks, Google can proactively revoke permissions from persistent bad actors, even if the individual site content doesn't immediately appear malicious. This allows for a more robust defense against evolving threats.
Google is also refining the notification permission model to provide users with greater control and reduce interruptions. A redesigned Android permission prompt aims to help users make more informed decisions about granting notification access. Furthermore, a new one-tap unsubscribe feature allows users to quickly revoke permissions from websites that send excessive or unwanted alerts, simplifying the process of managing notification subscriptions.
To further combat abuse, Google is enforcing stricter rate limits on push messages sent via Firebase Cloud Messaging (FCM). Domains that exceed a threshold of 1,000 push messages per minute receive HTTP 429 responses. Repeat offenders face even stricter limitations until they demonstrate sustained non-disruptive behavior. This mechanism helps mitigate large-scale notification spam while still allowing legitimate websites to utilize push notifications effectively.
The company's efforts extend to identifying and addressing deceptive content that might not be overtly malicious but still abuses notification systems. By analyzing website activity and user interaction patterns, Chrome can identify sites that employ dark patterns or misleading tactics to gain and maintain notification permissions, thereby protecting users from a wider range of unwanted communications.
Users who find their notification permissions have been revoked can review and restore them through Chrome's Safety Hub if they trust the website in question. This provides a balance between automated protection and user autonomy, ensuring that legitimate services are not unduly impacted while maintaining a strong defense against abuse.