2.2.18 (L1) Ensure 'Allow local file access to file:// URLs on these sites in the PDF Viewer' Is Disabled

Information

This setting will allow specified URLs to access file:// URLs in the PDF Viewer. By default all domains are blocked from accessing file:// URLs in the PDF Viewer

Blocking all domains, or a restricted list of domains, from opening a downloaded PDF file blocks the possibility of a malicious file being masked as a PDF. It could also block unknown or malicious code contained within the PDF that would run on the immediate opening within a browser tab.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Allow local file access to file:// URLs on these sites in the PDF Viewer

Impact:

Users will be required to open PDF files manually in the PDF Viewer or in the organization's PDF viewing application.

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|3.3

Plugin: Windows

Control ID: 5d830adcf7e6b6c55646021d0e9a0414450abdeb9ba0533773751e1f7c26f10a