Chrome Site Data Settings Still Spare Google.com
A researcher showed that Chrome can keep google.com cookies even when you tell it to delete site data on close. Here is the office-friendly version.
If your staff uses Google Chrome, you may already believe you turned on a privacy switch that wipes leftover cookies when the last window closes. This week a well-known security researcher showed that Chrome site data settings can still leave google.com data on the machine after that close. That is not a niche developer story. It is a shared-computer and shared-office story.
The finding landed on Hacker News on September 5, 2026 and climbed past 470 points within a day. Jeff Johnson reproduced it on two Macs running Chrome 152, with Chrome sign-in turned off and DuckDuckGo set as the search engine. He told Chrome to delete on-device site data when all windows close. After one Google search and a clean quit, google.com cookies and storage were still there. For a small business in Bradenton or Sarasota, that matters because browsers hold more than shopping carts. They hold client-portal sessions, saved form details, and the breadcrumbs of who searched what on a front-desk PC.
What happened
Six years ago, Johnson documented a similar Chrome bug: Google-owned sites were skipped when users asked Chrome to clear site data on quit. Google later fixed that report. The new write-up says the pattern is back, at least for www.google.com.
The test was simple on purpose. On-device site data was set to delete when every Chrome window closed. The tester was not signed into Chrome. The settings page showed no leftover site data. Then came one Google search. After closing the only window, and even after a full quit and relaunch, google.com still had cookies, local storage, and session storage.
Johnson said other sites did not get the same pass. He also pointed out he does not use Chrome as a daily driver, so he cannot pin the exact build where the behavior returned. He leans toward sloppy quality control rather than a secret plot. That is a fair posture. It is also not a reason for a business owner to ignore the setting.
The practical point is narrower than "Google is watching you." The practical point is this: a privacy control you already paid attention to may not do what the label implies for the one site most offices hit all day. If you rely on "delete data when I close Chrome" to clean a shared laptop, a loaner machine, or a front-desk kiosk, that control is incomplete.
Hacker News commenters offered competing explanations. Some said leftover Google data is a side effect of how Chrome keeps itself signed into Google services. Others asked for a control test against a second site. Johnson answered that google.com was the only holdout he found. You do not need to settle the motive debate to act. You only need to assume the setting is not a full wipe.
How it affects your business
Most Gulf Coast shops we visit run Chrome because it is already installed, staff know it, and half of your SaaS tools "work best in Chrome." That is fine until the same browser is the place people check Gmail, search a client name, open a booking calendar, and save a password prompt they should have dismissed.
Here is where the bug becomes an operations issue.
Shared desks. A realtor, clinic front desk, or warehouse office often has one PC that three people use. Closing Chrome is the ritual that is supposed to drop the last person's session. If google.com storage stays, the next person can inherit search history crumbs, a lingering Google session, or autofill traces you thought you erased.
Borrowed laptops. Storm season, travel, and "the office machine is in the shop" days create loaner devices. Staff search Google, open Docs, then hand the laptop back. A close-and-wipe setting that spares Google's own site is a weak checkout process.
Client-facing searches. Law, medical, accounting, and home-services teams search unique names, case numbers, and addresses. That query stream is not public, but it is still sitting in a browser profile. If the profile does not actually reset, the next user or the next technician can see more than they should.
False confidence. The larger risk is policy, not one cookie. If your written rule is "Chrome deletes everything on close," you have documented a control that is not true for the most-used site on the internet. Insurance questionnaires and customer contracts care about that kind of gap.
This is not an argument that Chrome is unusable. It is an argument that browser privacy is a setting you verify, not a checkbox you trust once. The same lesson shows up in our cybersecurity starter guide for Sarasota small businesses: identity and leftover sessions cause more local pain than exotic malware.
CISA's Cybersecurity Awareness Program keeps repeating a plain idea that fits this week: know what your tools actually do, and do not assume a vendor's default protects your office.
What to do
You can handle this in an afternoon. No new platform required.
1. Confirm the setting, then test it. In Chrome, open chrome://settings/content/siteData. If you use "Delete data sites have saved to your device when you close all windows," treat that as a preference, not a guarantee. Then open chrome://settings/content/all, search Google once, quit Chrome completely, reopen it, and see whether google.com is still listed.
2. Clear Google data by hand after shared use. On a front-desk or loaner PC, delete google.com site data from that same all-sites list before the next person sits down. Better: use a separate Windows or Mac user account per person so profiles do not mix.
3. Turn off Chrome sign-in on shared machines. Johnson's test already blocked Chrome sign-in. You should too on any PC that is not a named employee's daily device. A signed-in Chrome profile syncs more than bookmarks. It syncs the identity you were trying to drop.
4. Use a dedicated profile for work. Named staff should not mix personal Gmail, YouTube, and client search in one profile. Create a work-only Chrome profile, or switch the office standard to Microsoft Edge with a work profile if you already pay for Microsoft 365. Consistency beats brand loyalty.
5. Lock down the boring controls. Require a screen lock after a few minutes. Do not allow a shared local Windows account with no PIN. Turn on multi-factor authentication for Google Workspace or Microsoft 365. A leftover cookie is annoying. A leftover mailbox session is a business incident.
6. Write one sentence into your IT policy. "Closing a browser is not a data-wipe. Shared PCs use separate logins, and site data is cleared before handoff." That sentence will save an awkward conversation later.
7. Decide who owns browser hygiene. If nobody owns it, the front-desk machine will stay signed into whatever the last person touched. Assign a name, even if that name is us.
If you want a second pair of eyes on the actual PCs in your office, reach out through our contact page. We will tell you whether Chrome, Edge, or Safari is the least messy fit for how your team already works, and we will test the close-and-clear claim on your hardware instead of assuming the label is honest.
The Chrome site data settings story will get a patch, or it will get another blog post in six years. Either way, your clients do not care about Chromium QA. They care that the computer at your counter does not keep the last search.
---
Source: discussed on Hacker News (score 470+). Original article: Chrome again exempts Google from user site data settings by Jeff Johnson, September 5, 2026.