Decision RecordActivePublished without chair review
CRT-2026-017404 Aug 2026MORNING EDITIONDaily Roundtable
Chrome extension governance sprint
Run a five-business-day governance sprint: inventory force-installed extensions, separate managed from unmanaged devices, confirm owners and deployment paths, migrate legitimate local-policy installs to managed channels, and remove unowned or suspicious extension IDs. Do not bulk-purge extensions or roll back Chrome without evidence of malicious activity.
Current public guidance · the full record
What to do now
Under reviewAt a glanceRun a five-business-day Chrome extension governance sprint.
Day 0–1: inventory Chrome force-installed extensions from Chrome Browser Cloud Management, GPO, MDM, and local policy locations; flag every extension that changes New Tab or default search.
Day 2–3: split devices into properly managed devices and unmanaged or BYOD Windows and macOS devices; confirm the owner, business purpose, deployment path, and approving team for each flagged extension ID.
Day 4–5: migrate legitimate local-policy installs to managed channels such as Chrome Browser Cloud Management, GPO, or MDM; remove unowned or suspicious extension IDs.
Do not bulk-purge Chrome extensions or roll back Chrome unless local evidence shows malicious activity, broken business-critical search behavior, or another confirmed operational impact.
Why now
Under reviewAct now because the Roundtable evidence describes a near-term Chrome control-boundary change around policy-installed extensions that change New Tab or default search on unmanaged Windows and macOS.
The useful window is before administrators discover the issue through broken browser behavior or unreviewed extension removals.
The evidence supports a short governance sprint now because it can identify force-installed extensions, preserve legitimate managed deployments, and remove unowned or suspicious extension IDs without treating the issue as an emergency patch event.
The timing should still be described as based on current reporting because the packet does not include an authoritative Chrome or Google release note confirming exact rollout behavior.
Who is affected
Under reviewChrome administrators using Chrome Browser Cloud Management, GPO, or MDM are affected because they need to prove which force-installed extensions are legitimate and move any legitimate local-policy installs into managed deployment paths.
Operators of unmanaged or BYOD Windows and macOS devices are affected because the reported Chrome change is aimed at low-trust local policy on those platforms when extensions override New Tab or default search.
Security teams are affected because they need to distinguish unowned or suspicious extension IDs from approved enterprise search or browser-control deployments before removing anything.
Helpdesk and endpoint operations teams are affected because indiscriminate extension purges or Chrome rollback could break legitimate search workflows, while doing nothing leaves unmanaged local-policy abuse unresolved.
Properly domain- or MDM-authorized enterprise deployments are not described in the packet as the target of the reported Chrome change, but they still need inventory and ownership confirmation to prevent misclassification.
What supports this
Under reviewThe industry-impact assessment supports treating the Chrome issue as a one-week browser-governance sprint, not an emergency patch event; it specifically says current reporting concerns Chrome blocking policy-installed extensions that change New Tab or default search on unmanaged Windows and macOS and notes missing endpoint-count and loss data.
The defense-architecture assessment supports the operational sequence: inventory Chrome force-installed extensions from Chrome Browser Cloud Management, GPO, MDM, and local policy locations; flag New Tab or default-search changes; separate managed from unmanaged or BYOD devices; and avoid turning the issue into an overnight outage drill.
The peer calibration supports the managed-versus-unmanaged distinction and asks how to avoid breaking legitimate search deployments while remediating local-policy abuse.
The moderator synthesis supports the priority call: governance cleanup, not same-day emergency patching or board-level incident response, based on the evidence available.
The evidence review supports the sprint actions and separately flags the evidence gap: the packet lacks an authoritative Chrome or Google release note for exact rollout behavior.
How the Roundtable reached this
Under reviewThe Roundtable moved this from a possible browser security alarm to a bounded governance sprint.
The industry-impact view called it a one-week browser-governance sprint rather than an emergency patch event and noted missing endpoint-count and loss data.
The defense-architecture view converted that into a five-business-day sequence: inventory Chrome force-installed extensions, separate managed from unmanaged or BYOD Windows and macOS devices, confirm owners and deployment paths, migrate legitimate local-policy installs to Chrome Browser Cloud Management, GPO, or MDM, and remove unowned or suspicious extension IDs.
The moderator resolved the priority question by treating the issue as governance cleanup, not a same-day emergency patch or board-level incident, because the evidence described unmanaged local-policy abuse rather than properly domain- or MDM-authorized enterprise control.
The evidence review supported the action plan but flagged that the packet does not include an authoritative Chrome or Google release note confirming exact rollout behavior.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 13 candidate signals.
- Linker (AI panel role)Linker evaluated 13 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 31 evidence signals; 18 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 2 predictions and rejected 6 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 19 public/private findings.
- Arbiter (AI panel role)Arbiter produced 13 decision envelopes.
Key disagreement
Scout (AI panel role)
The packet lacks endpoint-count data and credible loss figures. The decision should change if malicious extension activity is actually found or if Chrome release behavior differs materially from the described plan.
Arbiter outcome
Arbiter outcome: new decision record. Supported browser-governance decision with no existing record match; rollout details should be phrased as current reporting unless vendor release notes are added.
Candidates considered
Considered 13 candidates · opened 1 · 12 not opened (12 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe uncertain part is not the governance action; it is the exact Chrome release behavior and fleet impact.
The packet describes current reporting that Google is preparing Chrome to block policy-installed extensions that change New Tab or default search on unmanaged Windows and macOS, but the evidence review says no authoritative Chrome or Google release source is included.
The packet also does not quantify affected endpoints, affected extension IDs, financial loss, helpdesk impact, or whether any specific local-policy install is malicious. Treat these as open checks during the five-business-day sprint rather than as reasons to delay inventory.
What evidence is missing
MissingThe packet is missing an authoritative Chrome or Google release note confirming the exact rollout behavior, scope, and timing for blocking policy-installed extensions that change New Tab or default search on unmanaged Windows and macOS.
It is also missing endpoint-count data, credible loss figures, and environment-specific telemetry showing how many Chrome force-installed extensions exist across Chrome Browser Cloud Management, GPO, MDM, and local policy locations.
No evidence in the packet shows confirmed malicious extension activity in a reader’s own fleet; that must come from local inventory, helpdesk, browser telemetry, EDR, or admin-console data.
What would change this
Under reviewChange the stance from governance sprint to urgent response if local telemetry confirms malicious Chrome extension activity, credential theft, browser hijacking at scale, or business-critical outage tied to New Tab or default-search enforcement.
Change the scope if an authoritative Chrome or Google release note says the rollout affects different platforms, different extension types, managed enterprise channels, or a different timeline than current reporting describes.
Change the action plan if inventory shows that legitimate local-policy installs cannot be migrated to Chrome Browser Cloud Management, GPO, or MDM within the sprint without breaking approved business workflows.
What to watch next
Under reviewAt the end of five business days, decide whether the sprint is complete by checking four concrete conditions: inventory coverage for Chrome force-installed extensions; owner and deployment-path confirmation for extensions that change New Tab or default search; migration of legitimate local-policy installs into Chrome Browser Cloud Management, GPO, or MDM; and removal of unowned or suspicious extension IDs.
Watch Chrome or Google release notes for confirmed rollout behavior and scope. Watch helpdesk tickets, browser telemetry, admin-console reports, and EDR alerts for spikes tied to New Tab or default-search changes, broken legitimate search deployment, or malicious extension behavior.
Escalate from governance sprint to incident response only if local telemetry shows malicious activity or material operational disruption.
Evidence basis
Pierre’s business-impact call turns C19 into a governance cleanup, not a crisis response. What changed here is the priority level: this is not a same-day emergency patch or board-level incident based on the evidence we have. It is a near-te…
Pierre, I’d make this a **one-week hygiene sprint, not an overnight outage drill**. **Day 0–1:** inventory Chrome force-installed extensions from Chrome Browser Cloud Management, GPO/MDM, and local policy locations; flag anything that chang…
James, quick calibration for C19: CyberBrief and BleepingComputer say Google is preparing Chrome to block policy-installed extensions that override New Tab/default search on unmanaged Windows and macOS, because local policy on low-trust unm…
Summary: Today’s roundtable treats this as a control-boundary day, not a single headline crisis. The highest-confidence immediate actions are to cut exposure on N-able N-central and Cisco firewall/FMC management paths where active exploitat…
Public value history
- 04 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 03 Aug 2026Methodology
How the panel reaches a Public Decision Record.