mirror of
https://bitbucket.org/chromiumembedded/cef
synced 2025-06-05 21:39:12 +02:00
Windows: Update cef_sandbox mitigations to match Chromium
This commit is contained in:
@@ -17,7 +17,11 @@ void InitializeSandboxInfo(sandbox::SandboxInterfaceInfo* info) {
|
||||
} else {
|
||||
// Ensure the proper mitigations are enforced for the browser process.
|
||||
sandbox::ApplyProcessMitigationsToCurrentProcess(
|
||||
sandbox::MITIGATION_DEP | sandbox::MITIGATION_DEP_NO_ATL_THUNK);
|
||||
sandbox::MITIGATION_DEP | sandbox::MITIGATION_DEP_NO_ATL_THUNK |
|
||||
sandbox::MITIGATION_HARDEN_TOKEN_IL_POLICY);
|
||||
// Note: these mitigations are "post-startup". Some mitigations that need
|
||||
// to be enabled sooner (e.g. MITIGATION_EXTENSION_POINT_DISABLE) are done
|
||||
// so in Chrome_ELF.
|
||||
}
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user