How to use this reference
Editorial lesson: distinguish a website's origin, the browser's network reachability and the user's intended destination class. Document which local integration actually needs permission and preserve a usable denial path. Treat the grant as permission to connect, not proof of application-level authorization. Review local-device authentication separately.
Before reading
- Browser origins, secure contexts and network address spaces
Context and limits
- The guide describes an evolving rollout and replaces the earlier Private Network Access preflight approach. Its initial transport limitations are historical, not a verified inventory of current gaps.
- Chrome 142 release notes identify an October 28, 2025 stable release and include local-to-loopback requests, beyond the original guide’s first-milestone scope. Chrome 145 notes identify February 10, 2026 and separate local and loopback permissions while retaining the older permission name as an alias.
- Chrome 147 release notes, last updated April 7, 2026, document permission gating for WebSockets and WebTransport and extend service-worker navigation coverage to subframes. Those notes expressly exclude main-frame navigations; permission coverage must not be generalized to every browser request.
- This is architectural guidance rather than a vulnerability or award report. Browser-wide implementation parity and current enterprise-policy coverage were not established.
Sources and provenance
- New permission prompt for Local Network Access Google Chrome for Developers · reviewed 2026-10-03
- Chrome 142 Google Chrome for Developers · reviewed 2026-10-03
- Chrome 145 Google Chrome for Developers · reviewed 2026-10-03
- Chrome 147: Local Network Access Google Chrome for Developers · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.