How to Block Payment Handlers Globally in Google Chrome

The Checkout Vulnerability

Google Chrome supports an advanced API known as “Payment Handlers.” This API allows third-party web applications and digital wallets to register themselves directly with your browser’s checkout flow. When you attempt to buy something online, these registered handlers can intercept the payment request and inject their own custom checkout screens, bypassing Chrome’s native autofill system. While designed for frictionless e-commerce, it is a significant financial security risk. Malicious or compromised web apps could potentially intercept your payment data. You must paralyze this API.

How to Block Payment Handlers Globally

You can permanently sever the browser’s ability to utilize third-party checkout injectors via Chrome’s Site Settings.

  1. Open the Google Chrome desktop browser.
  2. Click the three vertical dots (⋮) in the top right corner and select Settings.
  3. In the left-hand sidebar, click on Privacy and security.
  4. In the main window, click on Site settings.
  5. Scroll down to the “Permissions” heading and click to expand Additional permissions.
  6. Click on Payment handlers.
  7. Under the “Default behavior” heading, select the radio button for “Don’t allow sites to install payment handlers.”

Secured Transactions

The change takes effect instantly. Google Chrome will completely sever its internal connection to the Payment Handler routing system. The browser will permanently reject any request from a website attempting to register a custom digital wallet. When you check out online, you are now strictly forced to rely entirely on standard, encrypted web forms or Chrome’s native, secure autofill system, guaranteeing that unverified third-party code can never intercept your credit card data during a transaction.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.