How to Block Pop-ups on Chrome

The DOM Hijacking Vector

Modern malicious web environments frequently execute aggressive JavaScript payloads designed to mathematically hijack the Google Chrome WindowServer. These scripts spawn unauthorized, secondary UI matrices (pop-ups) or violently redirect your active tab to a fraudulent domain (e.g., a fake tech support alert). While the V8 engine possesses a native, algorithmic shield designed to intercept these unauthorized spawns, rogue domains often utilize exploit vectors to bypass it. You must instruct Chrome to mathematically enforce an absolute, global blockade against all secondary window generations.

How to Block Pop-ups on Chrome

Google engineered the architecture to allow for surgical, per-domain intervention (whitelisting a trusted corporate portal) or a thermonuclear, global override that physically prevents the DOM from executing the `window.open()` command.

1. Phase 1: Summon the Master Configuration Matrix:
* Launch Google Chrome.
* Click the three vertical dots in the absolute top-right corner of the interface.
* Select the stark text explicitly labelled Settings from the drop-down menu.
2. Phase 2: Target Acquisition (The Permissions Registry):
* In the left-hand navigation sidebar, click explicitly on Privacy and security.
* In the primary pane, click the module labelled Site settings.
* Scroll down to the absolute bottom of this pane, locating the block titled “Content.”
* Click explicitly on Pop-ups and redirects.
3. Phase 3: The Execution Trigger (Global Denial):
* Look at the “Default behavior” block at the top of the pane.
* Select the radio button explicitly labelled Don’t allow sites to send pop-ups or use redirects.
* The Mathematical Result: The V8 engine’s god-level shield is now active. If a rogue script attempts to spawn a window, Chrome will instantly kill the process in RAM and render a small, sterile “Pop-up blocked” icon (a browser window with a red ‘X’) inside the Omnibox.
4. Phase 4: The Surgical Override (Whitelisting):
* Some legitimate web applications (like banking portals or university testing software) mathematically require pop-ups to function. You must punch a hole through the shield for these specific domains.
* On that same settings page, scroll down to the block labelled Allowed to send pop-ups and use redirects.
* Click the stark Add button.
* Inject the exact alphanumeric URL (e.g., `https://secure.bank.com`) into the localized modal and click Add. The engine will now ignore the block command exclusively for that domain.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.