"Automatically de-elevate users launching chrome elevated. This CL is based on changes we've had in Edge, circa 2019, which attempts to automatically de-elevate the browser when it's run with the elevated part of a split / linked token," Stefan Smolen, who works with the Microsoft Edge team, wrote in a Chromium commit. Microsoft previously introduced a similar feature in 2019 to the Edge Browser. When users launched Edge with elevated permissions, a warning would appear, recommending that they relaunch the browser without administrative rights. When Chrome runs as an Administrator, it inherits elevated permissions, which means anything you download and open through the browser will also launch with Administrator rights, which can pose a serious security risk. Later, Microsoft modified the feature to automatically prevent the Edge browser from launching with elevated permissions. As spotted by Leo on X, Microsoft has confirmed that Chrome will now automatically de-elevate when users try to launch it with elevated permissions.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 14 May 2025 20:30:04 +0000