The Legacy Port Risk
Modern web browsers possess incredible hardware capabilities. Google Chrome includes an API known as the Web Serial API, which allows web applications to communicate directly with hardware devices connected to your computer’s legacy COM (serial) ports. While this is highly useful for engineers programming microcontrollers (like Arduino boards) directly from a web browser, it represents a massive security vulnerability for the average user. If a malicious website attempts to scan your serial ports and gains raw access to connected hardware, it could potentially extract data or exploit firmware. You must disable this API if you are not actively developing hardware.
How to Turn Off Serial Port Prompts
You can permanently revoke the browser’s permission to bridge your COM ports via the site settings.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (⋮) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Site settings.
- Scroll down and click on Additional permissions to expand the hidden menu.
- Click on Serial ports.
- At the very top of the screen, under “Default behavior,” select the radio button next to “Don’t allow sites to connect to serial ports.”
A Locked Gateway
The change is instantaneous. Google Chrome will completely shut down the Web Serial API engine. If an advanced web application attempts to execute a script to poll your computer for connected microcontrollers or legacy serial devices, the browser will silently block the request. You will never see a pop-up prompt asking for serial access, guaranteeing an absolute firewall between your physical hardware and the internet.