2.2.2 Ensure 'Control use of the Web Bluetooth API' is set to 'Enabled: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome has an API which allows the access to nearby Bluetooth devices from the browser with users consent.

Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API (2)

Allow sites to ask the user to grant access to a nearby Bluetooth device (3)

The recommended state for this setting is: Enabled with a value of Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API (2)

Rationale:

A malicious website could exploit a vulnerable Bluetooth device.

Impact:

If this setting is configured, websites no longer can access nearby Bluetooth device via the API (this includes web cameras, headphones, and other Bluetooth devices) and the user will never be asked.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Content Settings\Control use of the Web Bluetooth API

Default Value:

Unset (Same as Enabled: Allow sites to ask the user to grant access to a nearby Bluetooth device, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|15.9

Plugin: Windows

Control ID: 586082416e231f0fdd1916d2ed9055e52b3da299c5e5942b3a375783547b59a7