STIGQter STIGQter: STIG Summary: Google Android 15 COPE Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 13 May 2026:

Google Android 15 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].

DISA Rule

SV-267543r1137824_rule

Vulnerability Number

V-267543

Group Title

PP-MDF-333280

Rule Version

GOOG-15-008900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Google Android 15 device to enable the access control policy that prevents [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].

Note: All application data is inherently sandboxed and isolated from other applications. To disable copy/paste on the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Toggle "Disallow cross profile copy/paste" to "ON".

Check Contents

Review documentation on the managed Google Android 15 device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".

If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.

Vulnerability Number

V-267543

Documentable

False

Rule Version

GOOG-15-008900

Severity Override Guidance

Review documentation on the managed Google Android 15 device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

COPE:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".

If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.

Check Content Reference

M

Target Key

5654