How to Block HID Device Access Globally in Google Chrome

The Hardware Exploit Vector

Google Chrome supports an advanced API known as WebHID (Human Interface Device). This API allows web applications to bypass standard operating system drivers and communicate directly with physical hardware plugged into your computer—specifically gaming controllers, specialized keyboards, VR headsets, and custom button panels. While incredible for browser-based gaming, it is a significant security vulnerability. Malicious websites can exploit this direct bridge to silently probe your computer for vulnerable hardware peripherals, intercept raw input data, or attempt to re-flash device firmware. You must paralyze this API.

How to Block HID Device Access Globally

You can permanently sever the browser’s ability to interface with your physical input devices via Chrome’s Site Settings.

  1. Open the Google Chrome desktop browser.
  2. Click the three vertical dots (â‹®) in the top right corner and select Settings.
  3. In the left-hand sidebar, click on Privacy and security.
  4. In the main window, click on Site settings.
  5. Scroll down to the “Permissions” heading and click to expand Additional permissions.
  6. Click on HID devices.
  7. Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to HID devices.”

Total Physical Isolation

The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s raw HID driver stack. The browser is now permanently blind to the specialized gamepads or custom keyboards physically plugged into your machine. If a website attempts to execute a WebHID script to scan your USB ports for controllers, the API call will instantly auto-reject in the background, returning a null value. This guarantees absolute physical isolation between unverified web code and your computer’s input hardware.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.