A notification such as “Your phone is infected with a virus,” “Your subscription has expired,” or “Clean now” appearing in the corner of your screen is usually not the result of a genuine scan performed by the operating system. A website that was previously granted notification permission can send web push notifications even when the browser appears to be closed. The aim may be to direct you to a fake technical support line, phishing page, unnecessary subscription, or suspicious software download. The correct response is not to press the button in the alarming message, but to identify the source of the notification through the operating system and browser settings.
Do not interact with the notification first
Do not use the “scan,” “clean,” “renew,” or phone number button in the warning. If the notification comes from a website, clicking it opens the attacker’s page; looking like a genuine security product does not make it trustworthy. The card may display Chrome, Firefox, Edge, or a website domain in small print. Note the source or take a screenshot, then dismiss the notification. If the notification is full-screen, close the browser tab. If it will not close, terminate the browser through the operating system’s app switcher.
Distinguish a web notification from a system alert
A website generally must have been granted permission before it can send web push notifications. That permission may have been obtained through an “Allow” request on a fake “verify that you are not a robot” page. According to Mozilla, Firefox Web Push is opt-in, and permission can be revoked later. A browser logo or domain name on the notification is an important clue.
However, not every pop-up is a push notification. If it appears inside a tab only when you visit a particular page, it may be a pop-up or redirect. If it appears on the desktop or in the notification shade even when the browser is closed, it is more likely to be a site notification. If the source is an unknown standalone app, also review app permissions and recently installed programs.
Remove the site permission in Chrome
On Android, open Chrome and use the three-dot menu to go to Settings > Site settings or Permissions > Notifications. In the “Allowed” list, select any domain you do not recognize and block or remove its notification permission, or clear the site data. Menu names may vary depending on the Chrome and Android versions. Pressing and holding an active notification and opening its settings may also reveal the source app. However, disabling all Chrome notifications will also silence useful site notifications, such as calendar or meeting alerts. Preferably remove the problematic domain individually.
In Chrome on a computer, review Settings > Privacy and security > Site settings > Notifications. Find the domain sending the fake warning among the permitted sites and block or remove it. Google says it can automatically block deceptive or intrusive notifications; this protection does not mean that every permission granted previously is harmless.
Stop the notification in Firefox
In Firefox on a computer, open Settings > Privacy & Security. Under Permissions, open the settings beside Notifications. Select and remove the relevant site, or change its status to “Block.” “Remove” may allow the site to request permission again later, while “Block” also stops new requests from the same domain. Mozilla also explains that the “Send Notifications” permission can be revoked through the permission icon on an open page.
Run a security check after revoking permission
If you did not click the fake notification or download a file, simply revoking permission is sufficient in most cases. Even so, review browser extensions, recent downloads, and recently installed apps. Remove any extension or program you do not recognize. Update the browser and operating system through their official update channels, then run the built-in security scan. Do not download the “cleanup tool” recommended by the online warning.
If you entered a password through the warning, type the genuine service address yourself, change the account password, close active sessions, and enable multi-factor authentication. If you provided card details, contact your bank using the number on the back of the card or the communication channel in the bank’s official app. If you installed remote-access software, disconnect from the internet, remove the software, and obtain trusted support. Do not call the phone number displayed in the scammer’s warning.
Manage permissions instead of disabling every notification
Web notifications can be useful for parcel tracking, meetings, news, or business applications. The lasting solution is therefore not to silence every notification, but to keep the permission list under control. If a site says “Allow to continue” before showing its content, reject the request. Notification permission is not a technical requirement for solving a CAPTCHA, playing a video, or downloading a file.
After cleanup, restart the browser and check the notification permission list again. If the same warnings continue, investigate other browser profiles, synchronized extensions, and the operating system’s startup apps. If the symptom appears on multiple devices using the same account, synchronized extensions or settings may also be the source. A factory reset should not be the first step; identifying the source first is less disruptive and helps prevent the same mistake from recurring.
Research sources used: https://support.google.com/chrome/answer/3220216 https://support.mozilla.org/en-US/kb/push-notifications-firefox https://support.google.com/android/answer/9079661