2.94 (L1) Ensure 'Allow socket pool size randomization for proxies' is set to 'Enabled'

Information

This setting controls whether Chrome introduces subtle, unpredictable variations to its proxy network connection limits. Enabling this policy ensures the browser dynamically and randomly shifts connection capacity thresholds rather than adhering to a static, predictable limit.

Standard browsers use hard, predictable caps for simultaneous network connections (typically 128 sockets per proxy server). Malicious cross-site scripts can exploit these exact limits by intentionally flooding the socket pool and observing how the browser stalls or handles concurrent requests. This side-channel attack allows an attacker to map out and infer sensitive, cross-site browser state info that should normally be hidden.

Enforcing this policy randomizes connection capacity boundaries, destroying the mathematical predictability an external script needs to perform timing measurements or state leaking attacks. Leaving the policy unconfigured or disabled exposes enterprise web traffic to sneaky, cross-site tracking vectors.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Allow socket pool size randomization for proxies

Impact:

There should be no impact on the user.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.2

Plugin: Windows

Control ID: 8286ded0cd4b07d4379cc8a5eee63aba576ce6acd4d3d30058475652464e94e6