New Chrome update to fix a long-standing bug in user privacy for visited links

You May Be Interested In:Victoria’s hot seats LIVE updates: Our on-camera chat with Amelia Hamer in Kooyong; A battle of Wills: NOBS group highlights what’s missing north of Bell Street


It only took 20 years: Browsers have long exposed visited link history to malicious websites, enabling attackers to profile users or run phishing campaigns. By isolating link history with a new partitioning model, Chrome could close off an entire class of privacy attacks – potentially setting a new standard for safer web browsing.

Browsers have mishandled visited site tracking since the early days of the internet. Google is now working to fix the issue with Chrome. The browser’s next update will improve how it manages visited history, potentially rendering an entire class of exploits obsolete.

Google says Chrome 136 will be the first major browser to partition visited link history. Traditionally, the CSS “:visited” selector has let websites style visited links – typically changing them from blue to purple. Modern design enables far more customization, which attackers have exploited to extract users’ browsing history through side-channel attacks.

Cyber-criminals have exploited this issue by developing creative techniques to unmask users’ visited URL history, leading to serious security threats such as tracking, profiling, and phishing campaigns. Chrome 136 aims to shut down these exploits by restricting how websites apply styles through the visited selector.

The visited history has traditionally been unpartitioned, with no specific restrictions on where the selector could display previously clicked links. The new partitioning approach will ensure that a link appears as “visited” (default purple) only on the original site and within the frame where the user first clicked it.

Partitioning prevents cross-site leakage of visited link history, though Google plans to allow an exception for self-referencing links to preserve usability. The company also decided against fully deprecating the visited selector, arguing that it provides essential visual feedback for users.

Chrome 132 initially introduced partitioning as an experimental feature, and Google expects to enable it by default in Chrome 136. Other browsers have taken steps to prevent URL history leaks, but none have implemented partitioning or history isolation. If Chrome’s approach proves effective without degrading the user experience, rival browsers may adopt similar measures.

share Paylaş facebook pinterest whatsapp x print

Similar Content

AMD Fire Range laptop CPUs spotted in Asus gaming system benchmark
AMD Fire Range laptop CPUs spotted in Asus gaming system benchmark
Coinbase Revenue Falls Amidst Market Slowdown, Will the $25M Political Play Pay Off?
Coinbase Revenue Falls Amidst Market Slowdown, Will the $25M Political Play Pay Off?
Outrage grows over lack of headphone use in US airports and planes
Outrage grows over lack of headphone use in US airports and planes
Microsoft 365 Copilot launch sparks backlash over price hike and user issues
Microsoft 365 Copilot launch sparks backlash over price hike and user issues
Treyarch co-founder pleads guilty to drone collision with firefighting plane during LA wildfires
Treyarch co-founder pleads guilty to drone collision with firefighting plane during LA wildfires
Texas Instruments unveils MCU the size of a black pepper flake, ideal for next-gen wearables
Texas Instruments unveils MCU the size of a black pepper flake, ideal for next-gen wearables
Flash News Hub | © 2025 | News