Overview
- Google published a detailed Chrome Security blog on Tuesday explaining an integrated “Swiss cheese” strategy that combines Chrome client controls, Safe Browsing signals, and Firebase Cloud Messaging (FCM) server limits.
- Chrome now automatically revokes notification permissions for sites users do not recently engage with and for sites that repeatedly trigger suspicious-notification warnings; users can review and regrant those permissions in the Safety Hub.
- Google built behavioral detection that analyzes service worker activity and coordinated signals to find networks of sites that distribute deceptive or malicious notifications and proactively remove their access.
- On the FCM side Google enforces rate limits that cap disruptive domains at 1,000 messages per minute, return HTTP 429 errors when exceeded, and apply stricter throttles for repeat offenders until behavior normalizes.
- Google reports these measures cut unwanted Android notifications by more than 7 billion per day in Q1 2026 and says users saw fewer scams, less background activity and improved battery life while noting the company’s metrics come from its own systems.