The Offline App Packaging System
As web applications become increasingly complex, Google is constantly experimenting with new ways to make Progressive Web Apps (PWAs) function exactly like native desktop software. One of these experimental architectures is “Web Bundles.” This technology allows developers to package an entire website—including its HTML, CSS, JavaScript, and media assets—into a single, downloadable file. The “Desktop PWAs Web Bundles” flag in Chrome specifically governs the browser’s ability to interpret, install, and run these bundled web applications locally on your desktop, allowing them to function entirely offline without fetching assets from a remote server.
While this sounds excellent for offline productivity, Web Bundles have sparked significant controversy in the cybersecurity community. Because an entire application is packaged into a single opaque file, it becomes much harder for traditional antivirus software or network firewalls to scan the individual web assets for malicious code before they are executed by the browser. If a bad actor manages to slip a malicious script into a Web Bundle, Chrome might install and run it with the elevated privileges of a desktop PWA. If you prioritize strict security and prefer your web apps to load their assets transparently over a standard HTTPS connection where they can be inspected, you should disable this experimental packaging format.
How to Turn Off Web Bundles for PWAs
You can prevent Chrome from processing or installing Web Bundles via the experimental flags menu.
- Open Google Chrome.
- Click inside the main address bar at the top of the browser window.
- Type
chrome://flagsand press Enter. - On the “Experiments” page, use the search bar to look for Desktop PWAs Web Bundles.
- If the flag is available, click the dropdown menu next to it and change it from “Default” to Disabled.
- Click the blue Relaunch button at the bottom of the screen.
Upon restarting, Chrome will refuse to parse or install applications packaged as Web Bundles, forcing PWAs to rely on standard Service Workers and transparent network requests for offline functionality.