Information
This setting allows a list of names to be specified that will be exempt from HTTP Strict Transport Security (HSTS) policy checks, then potentially upgraded from http:// to https://.
The recommended state for this setting is: Disabled (0)
Allowing hostnames to be exempt from HSTS checks could allow for protocol downgrade attacks and cookie hijackings.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Disabled :
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\List of names that will bypass the HSTS policy check
Impact:
None - This is the default behavior.