1.9 Ensure 'Determine the availability of variations' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Configuring this setting allows specifying which variations are allowed to be applied in Google Chrome. Variations provide a means for Google to offer modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features.

Disabled (0): Allows all variations to be applied to the browser (also referred to as VariationsEnabled).

CriticalFixesOnly (1): Allows only variations considered critical security or stability fixes to be applied to Google Chrome.

VariationsDisabled (2), prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.

The recommended state for this setting is: Disabled (0)

NOTE: Google strongly believes there is no added security benefit for turning this to critical fixes as leaving it on increases the stability of the browser.

Rationale:

Google strongly recommends to leave this setting at the default (0 = Enable all variations), so fixes are gradually enabled (or if necessary, rapidly disabled) via the Chrome Variations framework.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled (same as VariationsEnabled):

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Determine the availability of variations

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653