2.4 Ensure 'Control use of the WebUSB API' is set to 'Enabled' with 'Do not allow any site to request access to USB devices via the WebUSB API'

Information

Google Chrome offers a API which allows the access to connected USB devices from the browser.
Rationale:
WebUSB is opening the doors for sophisticated phishing attacks that could bypass hardware-based two-factor authentication devices (e.g. Yubikey devices).

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Do not allow any site to request access to USB devices via the WebUSB API selected from the drop down:
Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Control use of the WebUSB API
Impact:
If this setting is enabled and set to Do not allow any site to request access to USB devices via the WebUSB API, websites can no longer access connected USB devices via the API which could also prevent 2FA USB devices from working properly.
Default Value:
Enabled: Allow sites to ask the user to grant access to a connected USB device

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: dc7d75c2a7259d4e8313308f9c6adf5ce54b9ef0b2aeb920aa1ddfb9098eda12