How to Block Serial Port Access Globally in Google Chrome

The Hardware Bridging Threat

Google Chrome supports an advanced API known as Web Serial. This API allows web applications to communicate directly with legacy serial ports (COM ports on Windows, /dev/tty on Linux) and modern USB devices that emulate serial connections, such as Arduino microcontrollers and specialized industrial hardware. While incredible for browser-based hardware programming, it is a massive security vulnerability. Malicious websites can exploit this direct bridge to silently probe your computer for attached engineering hardware or attempt to flash malicious firmware onto connected microcontrollers. You must paralyze this API.

How to Block Serial Port Access Globally

You can permanently sever the browser’s ability to interface with your COM ports via Chrome’s Site Settings.

  1. Open the Google Chrome desktop browser.
  2. Click the three vertical dots (⋮) in the top right corner and select Settings.
  3. In the left-hand sidebar, click on Privacy and security.
  4. In the main window, click on Site settings.
  5. Scroll down to the “Permissions” heading and click to expand Additional permissions.
  6. Click on Serial ports.
  7. Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to serial ports.”

Total Port Isolation

The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s serial driver stack. The browser is now permanently blind to any Arduino boards, 3D printers, or legacy COM hardware plugged into your machine. If a website attempts to execute a Web Serial script to scan for attached devices, the API call will instantly auto-reject in the background, returning a null value. This guarantees absolute physical isolation between unverified web code and your specialized electronics.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.