2.3 Ensure 'Control use of the Web Bluetooth API' is set to 'Enabled' with 'Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API'

Information

Google Chrome offers a API which allows the access to nearby Bluetooth devices from the browser with users consent.
Rationale:
A malicious website could exploit a vulnerable Bluetooth device.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API selected from the drop down:
Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Control use of the Web Bluetooth API
Impact:
If this setting is enabled and set to Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API, websites no longer can access nearby Bluetooth device via the API and the user will never be asked.
Default Value:
Enabled: Allow sites to ask the user to grant access to a nearby Bluetooth device

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: 15995bba5e9714ec1217ce0393ff7a505c53a8dd8f5da1d74797340523887821