4.2.6 Ensure 'Default Window Management permissions setting' Is 'Enabled' to 'Deny Permission'

Information

This setting can automatically deny access to the window management permissions by sites. It can be configured to either:

Disabled (2): Does not allow access to the Window Management permission by any site

Enabled (3): A site must ask the user any time it wants to access the Window Management permission.

If the value for DefaultWindowManagementSetting is not changed from the default, it will behave as if it is enabled. WindowManagementAllowedForUrls or WindowManagementBlockedForUrls will override this setting for any site that matches the configured URL patterns.

Rationale:

Denying access to Window Management can block rogue sites from opening additional browser windows. By blocking the additional windows, an organization could stop instances of nefarious sites being opened in locations of which the user is unaware.

Impact:

Disabling this would take away the functionality of the user to decide what sites get access to the Window Management permission and could impact organizational required URLs.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and Denies the Window Management permission on all sites by default:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Default Window Management permission setting

Default Value:

Allow Window Management permission access

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5)

Plugin: Windows

Control ID: 59fc5e2c047287bd7e15f538432bf5c1f54040dcbdfa88e4846ead8e1494c384