STIGQter STIGQter: STIG Summary: Google Chrome Current Windows Security Technical Implementation Guide Version: 2 Release: 11 Benchmark Date: 02 Jul 2025:

Use of the QUIC protocol must be disabled.

DISA Rule

SV-245538r961470_rule

Vulnerability Number

V-245538

Group Title

SRG-APP-000383

Rule Version

DTBC-0074

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Windows group policy:
1. Open the “group policy editor” tool with gpedit.msc.
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Google Chrome.
- Policy Name: Allow QUIC protocol
- Policy State: Disabled
- Policy Value: N/A

Check Contents

Universal method:
1. In the omnibox (address bar), type chrome://policy.
2. If QuicAllowed is not displayed under the Policy Name column or it is not set to False under the Policy Value column, this is a finding.

Windows method:
1. Start regedit.
2. Navigate to HKLM\Software\Policies\Google\Chrome\.
3. If the QuicAllowed value name does not exist or its value data is not set to 0, this is a finding.

Vulnerability Number

V-245538

Documentable

False

Rule Version

DTBC-0074

Severity Override Guidance

Universal method:
1. In the omnibox (address bar), type chrome://policy.
2. If QuicAllowed is not displayed under the Policy Name column or it is not set to False under the Policy Value column, this is a finding.

Windows method:
1. Start regedit.
2. Navigate to HKLM\Software\Policies\Google\Chrome\.
3. If the QuicAllowed value name does not exist or its value data is not set to 0, this is a finding.

Check Content Reference

M

Target Key

4081