A browser hijacker can change your homepage, redirect searches, and flood your screen with unwanted ads without asking.
This guide explains how to remove a browser hijacker and restore safe browsing across Chrome, Edge, Firefox, and Safari.
What a browser hijacker does
A browser hijacker is unwanted software or a malicious browser extension that alters browser settings for advertising, traffic redirection, or data collection.
Common changes include a new default search engine, a modified homepage, extra toolbars, and repeated redirects to unfamiliar websites.
In many cases, the hijacker arrives bundled with free software, fake updates, or deceptive download buttons.
It may also be installed through a malicious extension, a suspicious profile, or a program that injects browser settings at startup.
Signs your browser has been hijacked
You can often spot a browser hijacker by small but persistent changes that return after you fix them.
- Your homepage or new tab page keeps changing.
- Searches are redirected through unfamiliar domains.
- Extra extensions, toolbars, or search providers appear.
- Pop-ups, ads, or notification prompts increase sharply.
- Browser performance becomes slower or unstable.
- Settings reset after restart.
- Unknown apps appear in your installed programs list.
How to remove a browser hijacker from your device
The safest approach is to remove the source first, then repair the browser settings.
If you skip the underlying program or extension, the hijacker often returns.
1. Disconnect from suspicious websites and save important work
Close suspicious tabs and avoid clicking pop-ups or “scan now” alerts.
Save any open work, then restart the browser if it is repeatedly opening unwanted pages.
2. Uninstall suspicious applications
Check the installed apps or programs list on Windows, macOS, or your mobile device.
Remove anything you do not recognize, especially recently installed freeware, download managers, browser helpers, coupon tools, or fake security software.
- Windows: Open Settings, then Apps, then Installed apps.
- macOS: Review Applications and remove suspicious items, including helper tools.
- Android: Check installed apps and device admin permissions.
- iPhone and iPad: Remove suspicious profiles, VPNs, or browsers you did not install intentionally.
3. Remove suspicious browser extensions
Browser extensions are a common hijacker entry point.
Open your browser’s extension manager and remove anything unfamiliar, unused, or recently added from unknown publishers.
- Google Chrome: Menu, Extensions, Manage Extensions.
- Microsoft Edge: Menu, Extensions.
- Mozilla Firefox: Add-ons and themes, Extensions.
- Safari: Settings, Extensions.
If an extension reappears after deletion, it may be controlled by a local app, profile, or policy that must be removed first.
4. Reset browser settings
A browser reset removes many hijacker changes, including startup pages, search providers, pinned tabs, and temporary data.
Use the built-in reset or restore function in your browser to return settings to their default state.
- Chrome: Reset settings in the settings menu.
- Edge: Reset settings to default values.
- Firefox: Use the refresh or troubleshoot mode options.
- Safari: Clear history and website data, then review extensions and website permissions.
After the reset, recheck your homepage, search engine, and new tab page before reinstalling any optional extensions.
5. Clear cookies, cache, and site permissions
Hijackers often leave behind stored data that brings back redirects or advertising scripts.
Clear browsing data, including cookies, cached files, and site permissions such as notifications, pop-ups, camera access, and location access.
This step is especially important if you saw fake virus alerts, browser notifications from unknown domains, or repeated prompts to allow alerts.
6. Scan for malware with trusted security tools
Run a full scan with a reputable anti-malware product from a known vendor such as Microsoft Defender, Malwarebytes, Bitdefender, Kaspersky, or ESET.
A browser hijacker may be part of a larger unwanted software bundle, and scanning helps identify related adware, trojans, or potentially unwanted programs.
If the browser keeps reverting, use an offline scan or safe mode so the unwanted software has less chance to run while you clean the system.
7. Check your DNS, proxy, and startup settings
Some hijackers change network or startup settings to force redirects or reload themselves after reboot.
Review your proxy settings, DNS settings, startup apps, and scheduled tasks for anything unfamiliar.
- Proxy should generally be disabled unless your organization requires it.
- DNS should point to a trusted provider or your router’s legitimate configuration.
- Startup items should not include unknown updaters or browser helper tools.
How to remove a browser hijacker on Chrome, Edge, Firefox, and Safari
Each browser stores settings differently, but the core cleanup steps are the same: remove extensions, reset settings, clear site data, and verify permissions.
Google Chrome
- Remove unknown extensions.
- Check the startup pages and search engine settings.
- Reset Chrome settings if changes persist.
- Review notification permissions and site data.
Microsoft Edge
- Delete suspicious extensions.
- Review the startup and new tab configuration.
- Restore settings to default if necessary.
- Clear browsing data and site permissions.
Mozilla Firefox
- Remove add-ons from unknown publishers.
- Use the refresh feature if pages keep redirecting.
- Check homepage and search settings.
- Delete strange site permissions and saved data.
Safari
- Uninstall suspicious extensions.
- Review website notifications and pop-up permissions.
- Clear history and website data.
- Check profiles and remove anything unexpected.
How to prevent reinfection
Browser hijackers usually return because one risky download, extension, or permission was left in place.
Prevention focuses on reducing those entry points.
- Install software only from official vendors or app stores.
- Avoid bundled installers and skip optional offers.
- Use a reputable ad blocker if it fits your environment.
- Keep your browser and operating system updated.
- Review extension permissions before installing them.
- Decline notification prompts from unknown sites.
- Use standard user accounts when possible.
For businesses, endpoint protection, application allowlisting, and browser policy management can reduce hijacker exposure across managed devices.
When to seek deeper cleanup help
If redirects continue after resets and scans, the issue may involve a malicious profile, device management setting, or more advanced malware.
At that point, inspect synced browser profiles, verify administrator access, and consider backing up essential files before performing a clean operating system reinstall.
If banking, password, or identity data may have been exposed, change critical passwords from a clean device, enable multi-factor authentication, and review account activity for unauthorized logins.