Google Chrome to let Isolated Web App access sensitive USB devices

Chrome

Google is working on a new Unrestricted WebUSB feature, which allows trusted isolated web apps to bypass security restrictions in the WebUSB API.

WebUSB is a JavaScript API that allows web applications to access local USB devices on a computer. As part of the WebUSB specification, there are certain interface classes that are protected from being accessed via web applications to prevent malicious scripts from accessing potentially sensitive data.

The list of protected interface classes are audio, HID (Human Interface Device), mass storage, smart card, video, audio/video Devices, and wireless controller.

In addition, the WebUSB specification includes a block list of specific USB devices that cannot be accessed by the API, such as YubiKeys, Google Titan keys, and Feitian security keys, which are used for multi-factor authentication.

Google is now testing an “Unrestricted WebUSB” feature that allows Isolated Web Apps to access these restricted devices and interfaces.

“The WebUSB specification defines a blocklist of vulnerable devices and a table of protected interfaces classes that are blocked from access through WebUSB,” Google noted in a Chrome status update.

“With this feature, Isolated Web Apps with permission to access the “usb-unrestricted” Permission Policy feature will be allowed to access blocklisted devices and protected interface classes.”

Isolated web apps are applications not hosted on live web servers but packaged into Web Bundles, signed by their developer, and distributed to end-users. They are commonly created for companies to use in-house.

To make this work, these web apps must have permission to use the “usb-unrestricted” feature.

When an app with this permission attempts to access a USB device, the system first checks if it is on the blocklist of vulnerable devices. If it is, the device is normally removed from the access list.

However, this restriction is bypassed for web apps with the “usb-unrestricted” permission.

The system also checks whether the device is on the app’s list of allowed devices. If it is not, access is denied.

Additionally, the system will check if the accessed interface is marked as protected. If it is, and the app does not have the “usb-unrestricted” permission, access is denied.

Google’s proposed feature enables trusted isolated web apps to access a broader range of USB devices, allowing for greater functionality in a trusted setting.

Google says it plans to ship it for testing in Chome 128, which should be released in August 2024.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Verizon sues Chilmark over rejected cell coverage upgrades

A Verizon truck driving down Beach Road in Tisbury. —Eunki Seonwoo Verizon, one of the largest telecommunications companies in the nation, has sued Chilmark after the town denied upgrades by the cellular company that would have expanded cell coverage to its customers.  The federal lawsuit, filed by Verizon on March 16 in the U.S. District

What’s going on with Donut Lab?

In January, a Finnish-Estonian startup proclaimed it had developed a truly solid state battery, a holy grail for the technology industry. Donut Labs’ cell wasn’t just solid state, however. It claimed it was made from cheap and easily available materials, would charge to full in a few minutes and last for hundreds of years. If

Samsung Galaxy Watch Upgrade Adds Blood Pressure Tracking

Summary created by Smart Answers AI In summary: Tech Advisor reports that Samsung Galaxy Watch users in the US received FDA-approved blood pressure tracking, extending to older models like the Galaxy Watch 4. This health monitoring upgrade requires monthly calibration with an arm cuff and Wear OS 4 with Android 12+ for accurate readings. The

Pregnancy Tracking and Postpartum Care Apps Market Growth

Report Overview The Global Pregnancy Tracking and Postpartum Care Apps Market size is expected to be worth around US$ 1945.4 Million by 2035 from US$ 356.3 Million in 2025, growing at a CAGR of 18.5% during the forecast period 2026-2035. In 2025, North America led the market, achieving over 38.5% share with a revenue of

Middle East Electric Vehicle Market Surpasses USD 7.6 Billion

Middle East electric vehicle market grows with policy support, charging expansion, and rising EV adoption across region expansion Delhi, India – March, 2026 – Ken Research released its strategic market analysis titled “Middle East Electric Vehicle Market Report Size, Share, Growth Drivers, Trends, Opportunities & Forecast 2025-2030,” revealing that the current market size is valued

Iran’s IRGC labels 18 US companies as ‘terrorist”, names include Microsoft, Apple, IBM; sends message to employees: Leave your offices to …

Iran declares EU’s naval and air forces “terrorists organisation” in reciporocal move after action agaisnt IRGC Iran’s Islamic Revolutionary Guard Corps (IRCG) has reportedly sent warning to American companies. According to a report in CBS News, the warning, similar to one issued in March, sends warning to 18 US companies that include technology and finance

Apple less exposed as Iran war threatens India’s smartphone exports

Nikkei Asia reports that while Apple is less exposed to potential export disruptions out of India, shipments that rely on Middle East trade hubs could face significant declines in the coming weeks. Here are the details. Apple better prepared to handle disruptions Over the past year, India has emerged as one of Apples main alternatives

How San Diego is coping with high gas prices – San Diego Union-Tribune

With gas prices continuing their relentless climb, San Diego drivers scramble to find ways to absorb the economic blow. The financial pain is especially sharp for rideshare drivers like Abdi Warsame of San Carlos. While topping off his Toyota at a station in downtown San Diego on Tuesday morning, he estimated he’s paid close to

Apple’s coding language Swift can now be used to develop Android apps

There has existed a clear divide between Android and Apple over the past decade or so. Green bubbles vs. Blue bubbles, Safari vs. Chrome, and so many more differences have kept the two platforms separate. One of the most crucial differences between the two was the coding language that was used to develop their apps.

Study finds many NC students still using phones in class

RALEIGH Many North Carolina students are still using their phones in class despite a new state law banning their use during instructional time, according to data presented Tuesday to state lawmakers. An ongoing study of middle school students conducted by UNC-Chapel Hill showed only 60.7% said they were following school policy since the new state

No Signal: Survey in Japan Raises Concerns over Smartphones as Disaster Lifelines

Japan Data Society Disaster Apr 1, 2026 Smartphones have become the go-to communication tool for many Japanese households in case disaster strikes. However, a recent survey highlighted the need to be prepared for issues with connecting. Calling Home As more and more households in Japan rely on comprehensive communication apps on smartphones for day-to-day correspondence,

This is why free apps don’t exist anymore

You’ve already noticed this, but go ahead and browse the App Store or Google Play Store. Scroll through some of the apps and you’ll see plenty marked “Free.” In a good portion of them, you’ll also see “Contains in-app purchases.” The reality is that these apps are free to install, but not free to use.

IPL 2026: Minors hired to steal mobile phones during IPL match in Bengaluru

The stands were packed with spectators during the Indian Premier League (IPL) 2026 T20 cricket match between Royal Challengers Bengaluru and Sunrisers Hyderabad, at the M. Chinnaswamy Stadium, in Bengaluru on March 28, 2026. In a major breakthrough, the Cubbon Park police have cracked a series of mobile phone theft cases reported during the IPL

超過 20 個使用角度!Moft Dynamic Folio 超強 iPad 磁吸支架實試

眾籌已經超額接近 8 倍! 更新時間2026年3月31日週二 下午2:57 擅於利用摺紙原理來設計 iPhone、iPad 和 MacBook 支架配件的 Moft,他們最新作品是可以給 iPad 有超過 20 個不同使用角度的 Moft Dynamic Folio 磁吸支架,目前在 Kickstater 眾籌進度已經超額接近 8 倍之多!如無意外,Moft Dynamic Folio 也是會有一般零售版本,但如果想以優惠的眾籌價錢,並且是搶先擁有的話,可以考慮支持看看。但在此之前,Yahoo Tech 編輯已經親身試用過,感覺 Moft 團隊又再一次突破自己,可以說是最強的 iPad 支架了。 2026 新款 Dynamic Folio Case! Moft 在 2026 年推出全新 Dynamic Folio Case,加上了四個邊角來提升保護力,原來的多角度用法仍然繼承下來。 超過 20 個使用角度!Moft Dynamic Folio iPad 超強磁吸支架實試 Moft Dynamic Folio 就如過去同門產品一樣依靠磁吸方式,牢牢緊貼

0
Would love your thoughts, please comment.x
()
x