Google Says Chrome Cut 7 Billion Unwanted Android Notifications Per Day

Google Says Chrome Cut 7 Billion Unwanted Android Notifications Per Day

Google waded off billions of spammy and fraudulent notifications per day in Q1 of this year. Image: Google

Google says Chrome cut unwanted Android notifications by more than 7 billion per day using permission controls, abuse detection, rate limits, and on-device ML.

Aug 14, 2026

Seven billion unwanted notifications a day is a lot of noise to cut from Android devices.

Google says Chrome reduced unwanted notifications by more than 7 billion per day in the first quarter of 2026 by combining permission revocation, abuse detection, sender rate limits, and on-device machine learning.

The company is now using several defenses together. Chrome can revoke notification permissions, detect coordinated behavior across websites, flag suspicious notification content, and limit high-volume senders through Firebase Cloud Messaging (FCM).

That approach matters because it shifts some of the burden away from users, who would otherwise have to recognize every suspicious notification themselves.

Multiple approaches to address a single problem

Filtering out such a volume of unwanted notifications is a significant task, and Google has now revealed the behind-the-scenes process for doing so.

According to the company’s blog, Chrome is employing a “Swiss cheese” model to deal with unwanted notifications.

Google’s first line of defense is the infrastructure behind the notifications. Chrome can automatically revoke notification permissions from sites that appear abusive, repeatedly trigger warnings, or have become inactive, cutting off their ability to keep pushing alerts to a user’s device.

Chrome can automatically revoke notification permissions from sites that appear abusive, repeatedly trigger warnings, or have become inactive, cutting off their ability to keep pushing alerts to a user's device.
Image: Google

Google is also looking for signs that multiple websites may be working together.

Google can use signals such as service-worker activity to identify coordinated behavior, while its FCM adds another control by rate-limiting sites that send notifications at excessive volumes. Websites can be limited to 1,000 messages per minute, with repeat offenders facing tighter restrictions.

The company is also making it easier for users to turn off notifications without digging deep inside Chrome. Push notifications will now include an option to turn them off immediately.

Advertisement
Push notifications will now include an option to turn notifications off immediately.
Image: Google

More Google coverage

Chrome is building upon previous work

The 7-billion figure reflects more than Google’s latest changes.

Chrome’s notification defenses have been developing for months, including on-device Machine Learning that can analyze notification content locally rather than sending it to Google, an approach that helps keep the notification content end-to-end secured.

But Android’s hardware fragmentation leaves one question unanswered: how widely can these local protections actually run?

Google has not specified whether the on-device ML layer reaches budget and older devices as broadly as newer hardware, which could affect how consistently users receive the same level of protection.

The company keeps refining how secure Chrome notifications remain by now adding its recent multi-layered approach. In its own words, the “goal is to ensure that if abuse slips through one layer, another is there to catch it.”

The user still has a role to play

Even with all these defenses, Google cannot make the notification channel risk-free.

A notification can still be deceptive without triggering every automated defense. That means the user’s judgment remains the final layer of protection, making user awareness as important as Google’s protections.

There is also the possibility that automated security systems could get it wrong. Google hasn’t disclosed an incident in which these notification defenses made a specific mistake. But any system that automatically identifies and restricts content or websites has to contend with false positives. A legitimate site could be caught by an overly aggressive defense, frustrating users who actually want its notifications.

Other News: Google says Gemini has surpassed 1 billion monthly active users, marking a major milestone as it competes for scale in the rapidly growing consumer AI market. 

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.