Information
This setting will allow specified URLs to access file:// URLs in the PDF Viewer. By default all domains are blocked from accessing file:// URLs in the PDF Viewer
Rationale:
Blocking all domains, or a restricted list of domains, from opening a downloaded PDF file blocks the possibility of a malicious file being masked as a PDF. It could also block unknown or malicious code contained within the PDF that would run on the immediate opening within a browser tab.
Impact:
Users will be required to open PDF files manually in the PDF Viewer or in the organization's PDF viewing application.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Allow local file access to file:// URLs on these sites in the PDF Viewer