The Drive-By Download Risk
By default, Google Chrome allows you to click a download button, and a file instantly saves to your hard drive. However, a massive security vulnerability exists with “multiple files.” Some malicious websites are designed to trigger a “drive-by download.” When you click a single innocent-looking button to download an image, the website uses aggressive JavaScript to force Chrome to download that image, but then rapidly queue up ten more files (often malware executables) in the background. While Chrome usually blocks this and asks for permission, if you accidentally allowed a site to do this in the past, your machine is vulnerable. You must strictly enforce the multiple-file block globally.
How to Block Automatic Downloads
You can permanently revoke a website’s ability to trigger chained downloads via the Site Settings.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (⋮) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Site settings.
- Scroll down and click on Additional permissions to expand the hidden menu.
- Click on Automatic downloads.
- Under the “Default behavior” heading, click the radio button next to “Don’t allow sites to automatically download multiple files.”
Strict Enforced Queues
The change is instantaneous. Google Chrome will completely lock down its download queue engine. The browser will strictly enforce a “one click, one file” rule. If a website attempts to execute a script that downloads an image and then immediately attempts to download a secondary PDF, Chrome will violently terminate the second request. It will block the action and force a pop-up prompt to appear, guaranteeing that no website can ever silently spam your hard drive with hidden files.