How to Block MIDI Device Access Globally in Google Chrome

The Musical Instrument Exploit

Google Chrome supports the Web MIDI (Musical Instrument Digital Interface) API. This allows web applications to communicate directly with physical hardware synthesizers, electronic drum kits, and MIDI keyboards plugged into your computer’s USB ports. While useful for professional musicians using web-based digital audio workstations, it represents a highly specialized hardware vulnerability. Malicious websites can exploit this API to fingerprint your unique audio hardware setup, or theoretically send malicious SysEx (System Exclusive) commands to crash or re-program your expensive external synthesizers. You must paralyze this API.

How to Block MIDI Device Access Globally

You can permanently sever the browser’s ability to communicate with your USB audio hardware via Chrome’s Site Settings.

  1. Open the Google Chrome desktop browser.
  2. Click the three vertical dots (⋮) in the top right corner and select Settings.
  3. In the left-hand sidebar, click on Privacy and security.
  4. In the main window, click on Site settings.
  5. Scroll down to the “Permissions” heading and click to expand Additional permissions.
  6. Click on MIDI devices.
  7. Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to MIDI devices.”

Secured Audio Hardware

The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s MIDI routing daemon. The browser is now permanently blind to any synthesizers or keyboards plugged into your USB ports. If a website attempts to scan your system for attached MIDI hardware, the API call will instantly fail, returning a null value. This guarantees that random websites cannot interact with, map, or exploit your expensive physical music equipment.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.