2.31 (L1) Ensure 'Enable strict MIME type checking for worker scripts' Is Enabled

Information

This setting controls the ability for Google Chrome to upgrade to HTTPS from HTTP while navigating to certain sites. It can be configured to either:

- Disabled (0): Scripts for workers (Web Workers, Service Workers, etc.) use lax MIME type checking. Worker scripts with legacy MIME types, like text/ascii, will work.
- Enabled (1): Scripts for workers (Web Workers, Service Workers, etc.) require a JavaScript MIME type, like text/javascript. Worker scripts with legacy MIME types, like text/ascii, will be rejected.

If the value for StrictMimetypeCheckForWorkerScriptsEnabled is not changed from the default, it will behave as if it is enabled.

Setting this policy will require worker scripts to use more secure and strict JavaScript MIME types and ones with legacy MIME Types will be rejected.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable strict MIME type checking for worker scripts

Impact:

This should have no impact on users.

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 8eb918ba0690072cd2889b5d81a3c609e7feaa792f1ef252cff3395fe30e8256