1.18 Ensure 'Enable Renderer Code Integrity' is set to 'Enabled'

Information

This setting controls whether unknown and potentially hostile code will be allowed to load inside of Google Chrome.

The recommended state for this setting is: Enabled (1)

Rationale:

Disabling this setting could have a detrimental effect on Google Chrome's security and stability as unknown, hostile, and/or unstable code will be able to load within the browser's renderer processes.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable Renderer Code Integrity

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653