3.1.2 Ensure 'Default geolocation setting' is set to 'Enabled: Do not allow any site to track the users' physical location'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome supports tracking the users' physical location using GPS, data about nearby Wi-Fi access points or cellular signal sites/towers (even if you're not using them), and your computer's IP.

Disabled (0, same as 3)

Allow sites to track the users' physical location (1)

Do not allow any site to track the users' physical location (2)

Ask whenever a site wants to track the users' physical location (3)

The recommended state for this setting is: Enabled with a value Do not allow any site to track the users' physical location (3)

Rationale:

From a privacy point of view it is not desirable to submit indicators regarding the location of the device, since the processing of this information cannot be determined. Furthermore, this may leak information about the network infrastructure around the device.

Impact:

If this setting is disabled, chrome will no longer send data about nearby Wi-Fi access points or cellular signal sites/towers (even if you're not using them), and your computer's IP address to google.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to track the users' physical location:

Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Default geolocation setting

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(1), CSCv7|13

Plugin: Windows

Control ID: d85cbedb09ed184152eda030f05c7da229bcf483cddd6717927fcb62c78cae4f