Chrome again exempts google.com from site data deletion
Mac developer Jeff Johnson says Chrome is once again giving google.com special treatment when it comes to deleting site data automatically. Johnson has Chrome set to delete all site data whenever every open window is closed (chrome://settings/content/siteData), he is not signed into Chrome, and Chrome sign-in is disallowed on his machine. He also switched Chrome's default search engine from Google to DuckDuckGo before testing, to rule that setting out as a cause.
After closing his one Chrome window, Johnson checked chrome://settings/content/all and found that cookies, local storage and session storage for google.com had survived, something that persisted even after he quit and relaunched Chrome. Deleting the google.com data and repeating the test reproduced the same result. He says he confirmed the behavior on two different Macs running Chrome version 152.0.7977.83, and that as far as he can tell, google.com is the only site Chrome exempts from the deletion setting; inside Chrome's profile folder on disk, the retained data consists of cookies, local storage and session storage.
This is not the first time Johnson has found this bug. He first documented a similar exemption six years earlier, in a blog post that drew coverage from Hacker News, The Register, The Verge and Gizmodo; Google fixed the issue after his report. He says he is not certain when this newer version of the bug was introduced, and that he personally leans toward Hanlon's razor, chalking it up to incompetence rather than a deliberate scheme, while adding that Google's resources leave the company with no excuse for the mistake.
Key facts
- Developer Jeff Johnson reproduced the bug on two separate Macs running Chrome version 152.0.7977.83.
- Chrome was configured to delete all site data on closing every window, with Chrome sign-in disallowed and not in use.
- After closing Chrome, and even after quitting and relaunching it, cookies, local storage and session storage for google.com remained visible in chrome://settings/content/all.
- Johnson says google.com appears to be the only site Chrome exempts from the deletion setting.
- He first reported a similar exemption six years earlier in a post covered by Hacker News, The Register, The Verge and Gizmodo, and Google fixed that earlier bug.
Why it matters
Chrome is built by Google and remains the world's most used browser, so an exemption that keeps Google's own site data around after a user has explicitly asked for everything to be wiped looks like the company's product favoring the company's own site over the privacy setting a user chose. It is the kind of self-preferencing critics of dominant platforms point to, even though, as Johnson argues, the more likely explanation is a bug rather than a scheme.
Who it affects
Anyone running Chrome with the delete-site-data-on-close option turned on, the setting privacy-conscious users pick specifically to avoid leaving cookies and storage behind after a session. Johnson tested on Mac; the article does not say whether the same exemption shows up on Windows, Linux or other Chromium-based browsers.
How to use it
There is no product to adopt here, but the report gives Chrome users a concrete check: set chrome://settings/content/siteData to delete data on close, close every window, then look at chrome://settings/content/all afterward. If google.com data is still listed, it survived the deletion the setting promised. Users who want it gone can delete the google.com entry by hand after each session, or use a different browser for sessions where they want Google's data actually cleared.
How solid is it
The report rests on one developer's own testing, reproduced on two Macs, with a specific Chrome build number given (152.0.7977.83). Johnson has a track record on this kind of bug: he documented a similar exemption in 2020, that report was picked up by Hacker News, The Register, The Verge and Gizmodo, and Google fixed it afterward, which is independent corroboration that the underlying behavior is real and has occurred before. The article does not say whether Google has been notified of this new instance or has responded, and no one outside Johnson's own tests is quoted confirming the current occurrence.
Risks and caveats
The article gives no technical explanation for why google.com specifically is exempted, no Chrome release channel (stable, beta, dev or canary) for build 152.0.7977.83, and no indication of whether the bug also affects Windows, Linux or other Chromium-based browsers beyond the two Macs Johnson tested. It also does not say whether Johnson has reported this occurrence to Google or whether Google has acknowledged it, and no date is given for when the original 2020 version of the bug was fixed.
“As far as I can tell, www.google.com is the only site exempted by Chrome.”
— Jeff Johnson