Find notable cyber news and cases, enriched with sources, timelines, and signals.

Google Chrome expands Android notification anti-abuse controls with automatic permission revocation and rate limiting

Security Tool/Service
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

Google Chrome expanded its anti-abuse systems for Android notifications, reducing unwanted notification volume by more than 7 billion per day in Q1 2026. The controls now include automatic notification permission revocation for stale or suspicious sites and rate limiting for disruptive senders, cutting off deceptive notification traffic before it reaches users. The changes also target abuse tied to scams, malware, phishing attempts, and fraudulent payment requests.

Related Happenings

Google Play Protect adds warnings and app disabling for compromised SDK abuse

Security Tool/Service
H score11 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

About this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...

Rokarolla Android banking trojan activity

Malware Activity
H score26 First: 16.06.2026 16:15 Last: 16.06.2026 16:15 Sources 1

About this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...

Google Gemini on Android notification-injection bypass using Fake Context Alignment

Technical Analysis
H score16 First: 03.06.2026 22:11 Last: 03.06.2026 22:11 Sources 1

About this happening: Researchers found a notification-based prompt-injection bypass in Google Gemini on Android that could turn hostile notification text into unauthorized assistant actions*...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

Timeline

  1. 12.08.2026 04:15 2 articles · 2h ago

    Chrome expands Android notification anti-abuse controls

    Mitigation Patch Update

    Google expanded Chrome's Android notification anti-abuse controls with a layered "Swiss cheese" defense model that automatically revokes notification permissions from sites users have not interacted with recently or that repeatedly trigger suspicious-notification warnings, analyzes behavior across related websites and coordinated service-worker activity, and throttles disruptive senders to 1,000 messages per minute with HTTP 429 errors. Google said these controls reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026.

    Show sources