4.11 Ensure 'Import saved passwords from default browser on first run' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This setting controls if saved passwords from the default browser can be imported (on first run and later manually).

The recommended state for this setting is: Disabled (0)

Rationale:

In Chrome, passwords can be stored in plain-text and revealed by clicking the 'show' button next to the password field by going to chrome://settings/passwords/.

Impact:

If this setting is disabled, saved passwords from other browsers are not imported.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Import saved passwords from default browser on first run

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|16

Plugin: Windows

Control ID: b09d9a2fe9ca6d78a4909223bb0f670e4b70e2fe8419b5a755333fe4253ed25d