2.89 (L2) Ensure 'Dynamic Code Settings' Is Enabled

Information

Setting this policy to '1' switches on Arbitrary Code Guard (ACG) for the browser process. ACG prevents dynamic code being generated from within the browser process, which can help prevent potentially hostile code making unauthorized changes to the behavior of the browser process.

Memory corruption vulnerabilities that allow an attacker to write arbitrary code into executable memory space remain one of the most severe exploitation vectors against web browsers. Enforcing this policy applies strict Arbitrary Code Guard mitigation rules to the root browser process structure, fundamentally blocking code injection techniques and the execution of unverified payloads. By neutralizing the browser's ability to create dynamic or unsigned code paths on the fly, you drastically minimize the software attack surface and break weaponized exploitation chains attempting to gain system-level execution via browser context exploitation.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Prevent the browser process from creating dynamic code :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Dynamic Code Settings

Impact:

Switching on ACG might cause compatibility issues with third-party software (ex. specialized virtual desktop infrastructure (VDI) plugins, smart-card drivers, or locally deployed legacy PDF tools) that must run inside the browser process.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 7c31a7cc1098d9430cb848ff47dd1f6e218c985f1c48fc8aee3919684b5301c7