A fake virus warning may look like a system alert even when it actually came from a website that was allowed to send Chrome notifications. That distinction matters. Installing a random cleaner, reinstalling the browser or changing every pop-up setting is often unnecessary if the problem is a specific site's permission. The first task is to identify the sender and stop that permission, while preserving any useful reminders you intentionally receive.

Chrome separates website notifications, pop-up windows, redirects and browser extensions. Each has a different control. A notification can appear even when no tab for that website is open; a pop-up is generally a window or browser action initiated by a page. Some scams imitate security software or operating-system messages. This guide works from the least disruptive fix toward broader checks, rather than asking you to disable every useful browser feature.

The instructions refer to Chrome's site settings as documented by Google. Menu labels can vary with language, operating system and browser updates. Always use the browser's own settings interface, check the website domain before trusting an alert and avoid calling a telephone number displayed in a frightening notification. An unsolicited message is not evidence that your computer has been scanned or that its sender has access to your files.

Identify whether the alert is a website notification

Notice where the warning appears. A Chrome website notification may appear in the operating system's notification area with a site name or origin attached, while a browser pop-up usually opens inside or above a browser window. Do not click on the notification's big action button merely to investigate its source. Look for a small domain label, browser icon or notification history entry. The sender's actual website address is more useful than a title claiming to be from security support.

For the closely related practical context, read AI PC Buyer’s Guide: NPU, GPU and Memory Explained Without the Hype.

If several alerts arrive, write down the domains before closing them. This helps distinguish one abusive publisher from unrelated legitimate apps. Be cautious with misspelled names that resemble established security companies. A notification with dramatic language, a countdown, a toll-free number or a demand for immediate payment should be treated as an unverified claim. If you are unsure, open the security product independently rather than using the alert's link.

Remove permission from the offending site

In desktop Chrome, open Settings, then Privacy and security, Site settings and Notifications. Review the list of websites currently allowed to send notifications. Locate the unfamiliar or disruptive domain and change its permission to Block or remove the permission, depending on the control offered in your version. Google documents these steps in its Chrome notification help article. You can often reach the same control by visiting a website, selecting the site-information icon near the address and modifying Notifications.

Remove only the permissions you recognize as unwanted at first. If an important calendar, collaboration tool or news service sends alerts you genuinely use, leave it enabled while you investigate the suspicious sender. If the site no longer appears in the list, check whether Chrome has automatically removed permissions from a site you have not visited recently. The absence of a site permission means the next alert may be coming from a different source.

Know the difference between Block and Remove

Blocking a site explicitly tells Chrome not to display notifications from that origin. Removing an exception resets its permission so a future visit may bring another request, depending on browser settings and Chrome's protections. For a clearly abusive sender, an explicit block may be easier to understand and preserve. The exact buttons vary by platform, so read the description rather than assuming a Delete or Reset action has the same meaning in every Chrome release.

There is no need to erase your entire browsing history just to revoke one site's push permission. Clearing cookies can sign you out of useful accounts without resolving alerts from another permitted origin. After changing the notification permission, close the unwanted alert and observe whether new alerts from that source stop. If they continue, verify that the setting was changed in the correct Chrome profile and that another browser has not been left open.

Reduce disruptive notification prompts in the future

Chrome supports notification defaults, including blocking requests or allowing quieter prompts. If you rarely want website push alerts, a broad default block can be appropriate. If you need alerts from work tools or a few trusted services, quieter prompts may be a better compromise. The objective is to prevent unfamiliar pages from taking your attention while preserving the specific sources you deliberately selected. The browser's notification settings describe what each option will change.

For another relevant perspective, read Passkeys in 2026: Why Passwords Are Finally Losing Ground.

Before granting a new site's request, ask what benefit it actually offers. A restaurant menu, file download page or article does not normally require permission to send messages after you leave. Some sites make notification permission look like a prerequisite for playing media or proving you are human. Treat that pattern as a warning. Reject the request and use the site's core features only when they are genuinely available without granting unrelated permissions.

Check Chrome on Android separately

Chrome's Android notification controls overlap with system-level app notifications, and the available menus depend on Android version and manufacturer. A website may be blocked within Chrome even while Chrome itself remains allowed to display legitimate app notices. Start by inspecting the browser's site notification settings and identify the offending origin. If you turn off every notification for the Chrome app at the Android level, you may also silence notifications you actually wanted to keep.

When an alert appears on a phone, long-pressing it may show the app responsible or lead to notification controls. Use that clue to determine whether Chrome, another browser or an installed app sent the message. Avoid deleting an app based only on a claim made by the notification itself. Once you have identified the source, block the precise website permission or review the relevant application's notification settings as appropriate.

Do not confuse pop-ups with push notifications

Chrome normally blocks many intrusive pop-up windows, but that protection does not automatically cancel permissions previously granted for website push notifications. If advertising tabs or windows are opening while you browse, inspect Site settings, Pop-ups and redirects in addition to Notifications. Google's help documentation describes the controls separately. A successful change to the pop-up blocker should not be interpreted as proof that all notification permissions are safe or necessary.

Use a controlled observation: first close existing tabs, then wait to see whether a new notification appears without browsing. If it does, website push permissions or applications are more likely candidates. If an unwanted window appears only when you click a particular page, investigate that site's redirects and scripts. Avoid clicking through multiple prompts to reproduce suspicious behavior. Your aim is to narrow the source without increasing exposure to malicious pages.

Audit extensions without deleting everything

Extensions can alter browsing behavior, introduce new pages and display their own messages. Open Chrome's extension manager and review entries you do not recognize, especially those recently installed around the time unwanted alerts began. Examine permissions and the publisher information when available. If an extension appears suspicious, disable it and test whether the symptom changes. Removing every extension at once destroys the comparison and may interrupt password managers or accessibility tools.

Some legitimate extensions request broad access because of their features, but that does not justify permission you cannot explain. Prefer tools from identifiable publishers with clear functionality. If an extension was installed outside your usual process or cannot be disabled, investigate browser management policies and installed software. A work or school device may be managed by an administrator; bypassing those settings can be inappropriate and ineffective.

Look for signs of actual device compromise

A deceptive website notification alone is not proof of malware. However, additional symptoms deserve investigation: an unknown app launching at startup, the homepage repeatedly changing, unauthorized account sign-ins or security controls being disabled. Use the operating system's built-in security tools and update mechanisms. For Windows, inspect installed applications and run an appropriate scan using software you opened independently. Do not download a scanner advertised by the very warning you are trying to remove.

If there are credible signs that an account was compromised, change its password from a trusted device and review active sessions and recovery information. Where supported, enable phishing-resistant sign-in such as a passkey. The response should fit the evidence. One noisy permission is a browser-settings problem; confirmed unauthorized access is an account-security problem. Treating them as identical can waste time and create more risk than it removes.

How to investigate multiple Chrome profiles

Desktop Chrome can maintain separate profiles for personal, work and family browsing. Each profile may have its own extension list and website permissions. If you block a domain in one profile but continue seeing its alerts, check which profile was active when permission was granted. An alert's sender and app association can help you identify the relevant profile. Avoid assuming that a notification setting applies globally to every Chrome profile on your computer.

The simplest way to test is to close all Chrome windows, reopen only the profile you think is responsible and inspect its site notification exceptions. Repeat with another profile only if the symptom persists or records point there. Keep notes on which profiles permit the suspicious domain. On shared computers, make changes only to accounts you manage or have permission to configure; another person's legitimate reminders should not be silently disabled.

What to do when an alert pretends to be antivirus software

Fake security alerts use urgency to get users to click links, enter payment information, install software or contact a supposed support technician. The sender may use a familiar logo or name, but a website push notification is not an authenticated message from that organization. Close it, inspect the domain in Chrome settings and open your actual security software through its installed application or official website if you want to check device status.

Do not share remote access, credit-card details or one-time account codes with someone reached through an unsolicited alert. If you already provided information, respond based on what was shared: contact the payment provider for card exposure, review device security after remote access and update compromised account credentials. The notification settings fix stops the messages, but it cannot reverse financial or account actions taken earlier. Preserve relevant records when reporting a scam.

A safe troubleshooting order that preserves useful alerts

Begin by identifying the app and domain that sent the alert. Next, revoke that one site's notification permission. Then review your default notification-request behavior so future websites cannot easily repeat the pattern. If the alert stops, there is little benefit to deeper changes. If it persists, inspect other browser profiles, extensions and installed applications. This order protects useful browser settings and produces a clear record of what changed at each stage.

After each change, wait for a reasonable observation period rather than immediately making several unrelated changes. A sender may publish notices intermittently, so one quiet minute is not definitive. Keep a brief list of the domains you blocked and why. If a required work application unexpectedly stops alerting, return to its known official domain and adjust that specific permission rather than reverting every security setting on the browser.

Common questions and misconceptions

Blocking website notifications is not the same as blocking cookies, disabling JavaScript or disconnecting from the internet. Those settings control different functions and can break useful websites. Similarly, seeing Chrome's name beside a notification does not mean Google endorsed its message. Chrome is simply one application capable of relaying notifications from websites after permission is granted. The site identity and permission history are the relevant clues when deciding what should be trusted.

Another frequent mistake is allowing a notification permission merely to dismiss a full-screen request. A trustworthy page should make its actual purpose clear. If a website claims you must press Allow to verify that you are not a robot, examine whether you are being manipulated into subscribing to push messages. Chrome's controls make these permissions reversible, but the easiest fix is not granting them to a source you do not trust in the first place.

Fact-checked by GAMIC News Editorial Desk · Sources are listed above for verification.
GN
GAMIC News Editorial Desk

The GAMIC News editorial desk handles fast-moving briefs assembled from attributed source material.