How to Block Web Bluetooth Access Globally in Google Chrome

The Wireless Hardware Exploit

Google Chrome supports an advanced API known as Web Bluetooth. This API allows web applications to communicate directly with active Bluetooth Low Energy (BLE) devices in your immediate physical vicinity—such as heart rate monitors, smart home sensors, or IoT gadgets. While incredible for browser-based fitness dashboards, it is a massive security vulnerability. Malicious websites can exploit this direct bridge to silently probe your physical environment for vulnerable Bluetooth devices, intercept unencrypted data streams, or attempt to push malicious firmware updates over the air. You must paralyze this API.

How to Block Web Bluetooth Access Globally

You can permanently sever the browser’s ability to interface with your wireless radio stack via Chrome’s Site Settings.

  1. Open the Google Chrome desktop browser.
  2. Click the three vertical dots (⋮) in the top right corner and select Settings.
  3. In the left-hand sidebar, click on Privacy and security.
  4. In the main window, click on Site settings.
  5. Scroll down to the “Permissions” heading and click to expand Additional permissions.
  6. Click on Bluetooth devices.
  7. Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to Bluetooth devices.”

Total Radio Isolation

The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s raw Bluetooth driver stack. The browser is now permanently blind to the wireless airspace around your computer. If a website attempts to execute a Web Bluetooth script to scan for nearby devices, the API call will instantly auto-reject in the background, returning a null value. This guarantees absolute physical isolation between unverified web code and the vulnerable wireless gadgets in your home.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.