Chrome and Local Network Access

Body

Overview

Recent versions of Chrome include additional security protections for websites that attempt to communicate with devices or services on a user's local network.

Beginning with version 142, Chrome requires websites to obtain permission before making certain requests to local network resources. This feature is known as Local Network Access (LNA).

Local network resources can include:

  • Devices on private IP address ranges, such as routers, printers, and other network appliances.

  • Internal web servers and intranet services.

  • Applications or services running on the user's own computer through localhost or loopback addresses such as 127.0.0.1.

When a website attempts this type of connection, Chrome may display a prompt asking the user to allow the site to find and connect to devices on your local network. If permission is denied or has previously been blocked, functionality that depends on communication between the website and the local resource may fail.

Why did Chrome make this change?

The restriction is intended to prevent public websites from silently communicating with devices or services on a user's private network. This helps protect against attacks targeting local devices, including Cross-Site Request Forgery (CSRF), and limits websites' ability to use local network information for fingerprinting (identification).

What should users do?

If a trusted website requires access to a local device or locally installed application, users may need to select Allow when Chrome displays the Local Network Access permission prompt.

If access was previously denied, the site's permissions can be reviewed or changed through Chrome's site settings. Users should only grant local network access to websites they recognize and trust.

If the site needs to be allowed at an organizational level, submit a Help Desk ticket.

Details

Details

Article ID: 22063
Created
Mon 8/31/26 8:24 PM
Modified
Tue 9/1/26 8:56 AM