1. Keep the browser updated
Install browser updates when offered. Updates often fix security issues quietly in the background. Also keep Windows, macOS or your phone updated, because browser safety depends on the device too.
2. Leave phishing protection on
In Chrome, open Settings → Privacy and security → Security and check Safe Browsing. Standard protection is on by default; Enhanced protection offers stronger warnings but shares more security-related information with Google. Choose the level you are comfortable with.
3. Check the address, not just the page design
Before signing in or paying, inspect the web address carefully. A padlock or secure-connection symbol means the connection is encrypted; it does not prove that a site or seller is trustworthy. Watch for misspellings and extra words in the domain name.
4. Download only from a trusted source
Use the official website, Microsoft Store, Apple App Store or Google Play when possible. Avoid “download now” ads, cracked software and surprise update pop-ups. If you did not go looking for it, do not install it.
5. Review extensions
Remove extensions you do not need. An extension can read or change content on websites, so install only from the official browser store and check what access it requests.
6. Do not ignore a scary pop-up
A page saying “your computer is infected—call now” is commonly a scam. Do not call, install anything or give remote access. Close the tab; if it will not close, force quit the browser and reopen it without restoring the suspicious page.