2.5.1 Ensure 'Configure native messaging blocklist' is set to 'Enabled: *'

Information

Allows you to specify which native messaging hosts that should not be loaded.

Disabled (0): Google Chrome will load all installed native messaging hosts.

The recommended state for this setting is: Enabled with a value of *

NOTE: This needs to be handled carefully. If an extension is enabled, yet can't communicate with its backend code, it could behave in strange ways which results in helpdesk tickets + support load.

Rationale:

For consistency with Plugin and Extension policies, native messaging should be blocklisted by default, requiring explicit administrative approval of applications for allowlisting. An example of an application that uses native messaging is the 1Password password manager.

Impact:

A blocklist value of '*' means all native messaging hosts are blocklisted unless they are explicitly listed in the allowlist.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and the value of * set to Names of the forbidden native messaging hosts.

Computer Configuration\Polices\Administrative Templates\Google Chrome\Native Messaging\Configure native messaging blocklist

Default Value:

Unset (Same as Disabled, and users can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 27cd50d66224ba5a9c88c76800d16aed8da2c9cef31e57cccd1e49a61aaef6a3