2.2.4 Ensure 'Default notification setting' is set to 'Enabled: Do not allow any site to show desktop notifications'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome offers websites to display desktop notifications. These are push messages which are sent from the website operator through Google infrastructure to Chrome.

Allow sites to show desktop notifications (0)

Do not allow any site to show desktop notifications (1)

Ask every time a site wants to show desktop notifications (2)

The recommended state for this setting is: Enabled with a value of Do not allow any site to show desktop notifications (1)

Rationale:

If the website operator decides to send messages unencrypted Google's servers may process it as plain text. Furthermore, potentially compromised or faked notifications might trick users into clicking on a malicious link.

Impact:

If this setting is enabled and set to Do not allow any site to show desktop notifications, notifications will not be displayed for any sites and the user will not be asked.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to show desktop notifications selected from the drop down:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Content Settings\Default notification setting

Default Value:

Unset (Same as Enabled, with 'Ask every time a site wants to show desktop notifications')

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: 02f2d7b86f07188cdd8ed658897e40781dceac0bbff541212e31404a8c1fceaa