1.27 Ensure 'Instant apps' is set to 'Disabled'

Information

Disable instant apps.
The recommended state for this setting is: Disabled.

Rationale:

Instant apps allow you to use apps without installing them on your device. On clicking app links, the browser downloads and run app modules as desired by the user.
Having exposure to an app like this is dangerous since any malicious link could then potentially trick the user and then browser could download the app code and run on your device without requiring installation. Also, this feature defies enterprise security that relies on blacklisting or whitelisting apps based on installation. Hence, it is recommended to turn off instant apps.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Instant apps:

Tap on Settings Gear Icon.
Tap Apps & notifications.
Tap Advanced.
Tap Default apps.
Tap Opening links.
Toggle Instant apps setting to OFF position.

Impact:

Instant apps will not be available. The app links would open on the browser as other regular links.

Default Value:

By default, Instant apps is enabled.

See Also

https://workbench.cisecurity.org/files/2466

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|18

Plugin: MDM

Control ID: 433f28930e0151c80690da7f56820331bc0d5d5e960133ddc875895b91b5d892