Chromebook Extensions Risk Assessment

GAT Shield offers admins an extensive and in-depth view of users’ Chrome activity at all times.

Admins can audit users’ browsing activity set up alert rules based on user behavior, deploy web-filtering for end-users, and much more.

In this post, we’ll cover the ‘Extensions’ Section in GAT Shield, where you can audit, track, analyse and secure extensions on your Chromebooks and ChromeOS devices.

View all Chrome Extensions – Risk Assessment #

Navigate to Shield → Extensions → Extensions Explorer

The Extensions explore will present all the Extensions installed by the users of your domain.

  • Name – Name of the Extension
  • Version – What’s the current version of the extension
  • Permissions – List of all permissions required from your domain by the extension
  • Permission score – Our graded score based on the amount and types of permissions required by the application.
    • Low – low score assigned
    • Medium – medium score assigned
    • High – high score assigned
  • Enabled – Whether the extension is enabled or disabled.
  • Installed – When the extension was installed.
  • Removed – When the extension was removed.
  • Users – Which user installed this extension.

 

See Chrome Extension Permission score #

The Extension permission scores are useful to see and assess if the Extension is OK to be installed.

An extension permission list is defined here. Permission Scores‘ for an extension in Shield are based on the official permission list and have the scores assigned:

PermissionScorePermissionScore
alarms1power3
audio1pushMessaging3
audioCapture4serial1
browser4signedInDevices1
clipboardRead3socket3
clipboardWrite2storage3
contextMenus1syncFileSystem4
desktopCapture4system.cpu2
diagnostics1system.display4
dns1system.memory4
experimental1system.network4
fileBrowserHandler1system.storage4
fileSystem3tts4
fileSystemProvider4unlimitedStorage4
gcm4usb3
geolocation3videoCapture4
hid1wallpaper1
identity1webview2
idle1webRequest2
infobars1webRequestBlocking2
location1tabs1
mediaGalleries1management4
nativeMessaging3history3
notificationProvider2identity1
notifications2downloads3
pointerLock2identity.email3

‘The Total Permission Score’ for an extension (presented in the UI) is calculated as max of [list of ‘Permission Score’ values for an extension]  

High Risk’ extensions are classed as such because they require sufficient resources in chrome that they could crash it.

GAT Shield is classifying ‘High Risk’ extensions using ‘Permission Score’:

  • <= 1  N/A
  • =   2  Low
  • =   3  Medium
  • >= 4  High

Often these extensions need the resources they ask for, we are just drawing your attention to them.

This website uses cookies to ensure you get the best experience on our website