2.3.7 Ensure 'Control availability of extensions unpublished on the Chrome Web Store' Is Disabled

Information

This policy disables any extensions in Google Chrome that were downloaded from the Chrome Web Store and are now unpublished. The policy can be configured to either:

Enabled (0): Allow unpublished extensions

Disabled (1): Disable unpublished extensions

If the value for ExtensionUnpublishedAvailability is not changed from the default, it will behave as it is enabled.

Note: Off-store extensions such as unpacked extensions installed using developer mode and extensions installed using the command-line switch are ignored. Force-installed extensions that are self-hosted are ignored. All version-pinned extensions are also ignored.

Rationale:

Disabling unpublished extensions will remove the ability to run any extensions that are no longer being updated or patched.

Impact:

This may disable extensions commonly used by users in your organization.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Disable unpublished extensions:

Computer Configuration\Policies\Administrative Templates\Google Chrome\Extensions\Control availability of extensions unpublished on the Chrome Web Store.

Default Value:

Allow unpublished extensions

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|9.4

Plugin: Windows

Control ID: bbf47ca45adb641501febd9ba59f9a193717457abbd6676df0a83a5dab89d69c