How to Allow Pop Ups on Google Chrome

The Security Override Vector

By default, the Google Chrome engine executes a strict, mathematical blockade against all automated pop-up windows. This is a critical security architecture designed to prevent malicious JavaScript from spawning hundreds of fraudulent advertisements or phishing portals. However, many legitimate enterprise architectures—such as corporate banking portals, secure document signing platforms, and university grading systems—rely on spawning authenticated pop-up windows to execute transactions. To interact with these systems, you must manually instruct the Chrome kernel to bypass its security matrix for that specific domain.

How to Allow Pop Ups on Google Chrome

Chrome provides two execution pathways: a rapid, localized override for the specific website you are currently viewing, and a master registry setting to define global permissions.

1. Method 1: The Rapid Context Override (The Best Method):
* Navigate to the specific secure website that is attempting (and failing) to launch a pop-up window.
* Look at the absolute far right edge of the Omnibox (the URL address bar).
* If Chrome has just intercepted a pop-up, you will see a tiny icon depicting a browser window with a red ‘X’ over it.
* Click that red ‘X’ icon.
* A small dialogue box will drop down. Select the radio button explicitly labelled: Always allow pop-ups and redirects from [website URL].
* Click Done. The kernel instantly writes an exception rule for that specific domain into the local registry. You must now refresh the page (press F5) for the pop-up to spawn successfully.
2. Method 2: The Master Registry Override (Global Settings):
* If you need to manually whitelist multiple domains simultaneously.
* Click the three vertical dots in the absolute top-right corner of the Chrome interface.
* Select Settings from the dropdown menu.
* In the left-hand navigation sidebar, click on Privacy and security.
* In the main pane, click on Site settings.
3. The Target Acquisition (The Permissions Matrix):
* Scroll down the Site Settings page to the “Content” sub-heading.
* Click on Pop-ups and redirects.
4. The Execution Trigger (Whitelisting):
* You are now viewing the master control panel.
* Warning: Do NOT change the master toggle at the top to “Sites can send pop-ups.” This mathematically destroys your security across the entire internet.
* Instead, scroll down to the section titled Allowed to send pop-ups and use redirects.
* Click the blue Add button.
* Type the exact URL of the trusted domain (e.g., `[*.]chase.com`) and click Add to finalize the cryptographic exception.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.