STIGQter STIGQter: STIG Summary: Google Chrome Current Windows Security Technical Implementation Guide Version: 2 Release: 11 Benchmark Date: 02 Jul 2025:

Session only based cookies must be enabled.

DISA Rule

SV-245539r960864_rule

Vulnerability Number

V-245539

Group Title

SRG-APP-000080

Rule Version

DTBC-0045

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Windows group policy:
1. Open the group policy editor tool with gpedit.msc
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings.
- Policy Name: Default cookies setting
- Policy State: Enabled
- Policy Value: Keep cookies for the duration of the session

Check Contents

Universal method:
1. In the omnibox (address bar), type chrome://policy
2. If the policy "DefaultCookiesSetting" is not shown or is not set to "4", this is a finding.

Windows method:
1. Start regedit.
2. Navigate to HKLM\Software\Policies\Google\Chrome\DefaultCookiesSetting.
3. If this key does not exist, or is not set to "4", this is a finding.

Vulnerability Number

V-245539

Documentable

False

Rule Version

DTBC-0045

Severity Override Guidance

Universal method:
1. In the omnibox (address bar), type chrome://policy
2. If the policy "DefaultCookiesSetting" is not shown or is not set to "4", this is a finding.

Windows method:
1. Start regedit.
2. Navigate to HKLM\Software\Policies\Google\Chrome\DefaultCookiesSetting.
3. If this key does not exist, or is not set to "4", this is a finding.

Check Content Reference

M

Target Key

4081