The Hardware Exploit Vector
Google Chrome supports an advanced architecture known as the Web Serial API. By default, this protocol allows complex web applications (like browser-based hardware configuration tools or online 3D printer interfaces) to request direct, low-level, bidirectional communication with devices connected to your computer’s serial ports (COM ports). While useful for flashing firmware onto a microcontroller directly from a webpage, it is a massive security vulnerability. Malicious websites exploit the Web Serial API to execute unauthorized code against vulnerable legacy hardware, potentially hijacking industrial controllers, specialized diagnostic equipment, or network switches without touching the operating system’s standard file management stack. You must paralyze this API.
How to Block Serial Port Access Globally
You can permanently sever the browser’s ability to interface with your physical COM ports via Chrome’s Site Settings.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (â‹®) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Site settings.
- Scroll down to the “Permissions” heading and click to expand Additional permissions.
- Click on Serial ports.
- Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to serial ports.”
Total Peripheral Isolation
The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s serial hardware enumeration daemon. The browser is now permanently blind to the legacy devices plugged into your motherboard. If an untrusted website attempts to execute a script to identify or manipulate an attached COM device, the API call will instantly auto-reject in the background, returning a null value. This guarantees absolute hardware isolation, ensuring that unverified web code remains entirely separated from your physical peripherals.