{"packId":"en-304-617","packVersion":"0.1.0","standard":{"reference":"ETSI EN 304 617","title":"Cybersecurity (CYBER); CRA; Cybersecurity requirements for web browsers","status":"INTERIM DRAFT under open consultation — subject to substantial change before publication; approved versions come only from the ETSI Documentation Service. Not cited in the Official Journal: conformance confers NO presumption of conformity today.","draftVersion":"v0.1.1 (2026-04-04)","sourceUrl":"https://labs.etsi.org/rep/stan4cra/en-304-617","sourceCommit":"f774a5fe","retrieved":"2026-09-02","retrievedAt":"2026-09-02","license":"BSD-3-Clause, © ETSI. Redistributed with attribution as the license requires; the verbatim requirement and assessment text below is reproduced from the interim draft.","licenseText":"Copyright 2025 ETSI\n\nRedistribution and use in source and binary forms, with or without\nmodification, are permitted provided that the following conditions are met:\n1. Redistributions of source code must retain the above copyright notice,\n   this list of conditions and the following disclaimer.\n2. Redistributions in binary form must reproduce the above copyright notice,\n   this list of conditions and the following disclaimer in the documentation\n   and/or other materials provided with the distribution.\n3. Neither the name of the copyright holder nor the names of its contributors\n   may be used to endorse or promote products derived from this software without\n   specific prior written permission.\n\nTHIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS \"AS IS\" AND\nANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED\nWARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.\nIN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,\nINDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,\nBUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,\nDATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF\nLIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE\nOR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED\nOF THE POSSIBILITY OF SUCH DAMAGE."},"appliesTo":{"annexIIIItem":"Standalone and embedded browsers","category":"important-1","craCategory":"important-1","note":"Attaches to a product whose CRA classification matched the Annex III browsers item, or manually."},"scope":"The present document specifies technical requirements and corresponding assessment criteria for web browsers related to cybersecurity. The products with digital elements in scope, thereafter \"the products\" are specified within the \"technical description\" of the \"category of product\" number \"2\". by the Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council. [i.2\\], which is as follows:\n\n> Software products with digital elements that enable end users to access, render, and interact with web content and services hosted on servers that are connected to networks such as the Internet. They typically include a browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of temporary or persistent data from websites (cookies).\n>\n> This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded browsers intended for integration into another system or application as well as browsers with AI agent integration.\n\nThe products are only covered within the product context described in clause 4. The present document specifies technical characteristics and methods of assessment for:\n- **Standalone web browsers**: standalone applications that fulfill the functions of web browsers\n- **Embedded web browsers**: reusable software components which act as a web browser integrated into a larger application\n\nThe present document covers those Products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 [i.1\\] Annex I under the conditions identified in annex A of this document.","applicabilityIntro":"The technical requirements of the present document apply under the product context described in Clause 4, which shall be in accordance with its intended use. The equipment shall comply with all applicable technical requirements of the present document at all times when operating in such product context.\n\nThe applicability of the requirements to the Use Cases / Security Profiles are defined below:\n\nEditor's Note: If there is a matrix mapping the use cases to the technical requirements of the standard, it should be inserted in this clause. Alternatively, there can be such a matrix/mapping in each subclause below.\n\nThe extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.","useCases":[{"id":"UC-CONS","title":"General Purpose Web Browser Use Case","description":"**UC-CONS**: Standalone web browser for individual consumers\n\n- Used for accessing the whole web, including sensitive/critical applications.\n- Users are, in general, not educated or aware of cybersecurity issues.\n- Installed on mobile phones, desktop and laptop computers, televisions, larger embedded devices, etc.\n- Includes flexible settings, including high-risk features like developer mode, etc."},{"id":"UC-INST","title":"Enterprise Browser Use Case","description":"**UC-INST**: Standalone web browser for institutional or enterprise use, including critical infrastructure\n\n- Central IT administration may set \"enterprise policy\" to configure security-related policies.\n- Used in environments which are often taking other sorts of precautions, e.g., at the network/VPN level, physical access, etc.\n- May be used to access \"internal\" websites which may have been developed with more or less attention to security, or which have special authentication needs."},{"id":"UC-ETAB","title":"Embedded Browser Use Case","description":"**UC-ETAB**: Browser-like tab component for embedding in a larger application\n\n- Used by embedding applications to enable linking to outside content while encouraging the user to return to the parent application\n- Intended to facilitate access to just one website, omitting any UI to enter URLs or searches\n- Grants access via links to the rest of the World Wide Web; users may \"forget\" that they are inside another application\n- Typically no settings UI, and no integration into enterprise policy.\n- Could share the state with the user's default browser."}],"craMap":[{"craRef":"Annex I, Part 1, (1)","clauses":"5"},{"craRef":"Annex I, Part 1, (2)(a)","clauses":"5.2"},{"craRef":"Annex I, Part 1, (2)(b)","clauses":"5.3"},{"craRef":"Annex I, Part 1, (2)(c)","clauses":"5.4"},{"craRef":"Annex I, Part 1, (2)(d)","clauses":"5.5"},{"craRef":"Annex I, Part 1, (2)(e)","clauses":"5.6"},{"craRef":"Annex I, Part 1, (2)(f)","clauses":"5.7"},{"craRef":"Annex I, Part 1, (2)(g)","clauses":"5.8"},{"craRef":"Annex I, Part 1, (2)(h)","clauses":"5.9"},{"craRef":"Annex I, Part 1, (2)(i)","clauses":"5.10"},{"craRef":"Annex I, Part 1, (2)(j)","clauses":"5.11"},{"craRef":"Annex I, Part 1, (2)(k)","clauses":"5.12"},{"craRef":"Annex I, Part 1, (2)(l)","clauses":"5.13"},{"craRef":"Annex I, Part 1, (2)(m)","clauses":"5.14"},{"craRef":"Annex I, Part 2","clauses":"5.15"}],"topics":[{"id":"5.2","clause":"5.2","title":"No known exploitable vulnerabilities","overview":"Proposed ESR code: KEV\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (a).\n\n> NOTE: It is proposed that a cross-vertical task force could work on the technical requirements to be included in this clause.","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-KEV-1","clauseRef":"5.2","requirement":"The product shall incorporate only components, including third party and open source elements, for which no known exploitable vulnerabilities exist at the time of release.\n\nNote: The manufacturer may relay on documentation in the form of an Software Bill of Materials (SBOM) as well as reasoning of why known vulnerabilities are not exploitable under the applicable, expected operational environment.","applicability":{},"assessment":null},{"id":"REQ-KEV-2","clauseRef":"5.2","requirement":"In accordance with the requirement to apply effective and regular tests to the security of the product, the product shall be tested to demonstrate the absence or mitigation of known exploitable vulnerabilities.\n\nNote: To demonstrate compliance, the manufacturer may rely on manual security testing (e.g., penetration testing), automated vulnerability scanners, or a combination of both, depending on what is most comprehensive and technically feasible for the product's technology stack.","applicability":{},"assessment":null},{"id":"REQ-MEM-KEV-1","clauseRef":"5.2","requirement":"The web browser's source code that parses untrusted, non-trivial data, shall undergo ongoing automated dynamic analysis to identify vulnerabilities.\n\nExample: Code that parses media files is subjected to fuzz testing in an environment that enables the detection of memory safety errors, such as LLVM sanitisers.","applicability":{},"assessment":{"accId":"ACC-MEM-KEV-1","reference":"The web browser's source code that parses untrusted, non-trivial data shall undergo ongoing automated dynamic analysis to identify vulnerabilities.","objective":"The manufacturer conducts ongoing automated dynamic analysis to identify vulnerabilities in the web browser.","preparation":"- Documentation describing how code is selected to undergo automated dynamic analysis.\n- Documentation describing how, and how often, the automated dynamic analysis is conducted.\n- Documentation describing a methodology for measuring and improving the code coverage of their dynamic analysis tools over time.\n- Code coverage reports.\n- A sample of bug tracker entries generated by each dynamic analysis technique described in the documentation.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. Review the code coverage reports.\n3. Review the bug tracker entries.","verdict":"- **Pass**:\n    - The documentation describes a methodology for how code is selected to undergo automated dynamic analysis.\n    - The documentation describes one or more dynamic analysis techniques and how they are automated and integrated into the web browser's software development lifecycle.\n    - The documentation describes a robust methodology for measuring and improving the code coverage of their dynamic analysis tools over time.\n    - Code coverage reports demonstrate that the dynamic analysis achieves the coverage targets defined in the manufacturer's methodology, or show documented progress toward those targets.\n    - The bug tracker entries show evidence of being filed in an automated fashion as described in the documentation.\n    - The bug tracker entries describe identified vulnerabilities.\n    - The bug tracker entries show the identified vulnerabilities have been fixed.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation and bug tracker entry review.","guidance":""}},{"id":"REQ-MEM-KEV-2","clauseRef":"5.2","requirement":"The product's source code shall undergo ongoing automated static analysis to identify vulnerabilities.\n\nExample: Via LLM code analysis, static application security testing tools.","applicability":{},"assessment":{"accId":"ACC-MEM-KEV-2","reference":"The web browser's source code shall undergo ongoing automated static analysis to identify vulnerabilities.","objective":"The manufacturer conducts ongoing automated static analysis to identify vulnerabilities in the web browser.","preparation":"- Documentation describing the automated static analysis that is conducted.\n- A sample of bug tracker entries generated by each static analysis technique described in the documentation.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. Review the bug tracker entries.","verdict":"- **Pass**:\n    - The documentation describes one or more static analysis techniques and how they are automated and integrated into the web browser's software development lifecycle.\n    - The bug tracker entries show evidence of being filed in an automated fashion as described in the documentation.\n    - The bug tracker entries describe identified vulnerabilities.\n    - The bug tracker entries show the identified vulnerabilities have been fixed.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation and bug tracker entry review.","guidance":""}},{"id":"REQ-MEM-KEV-3","clauseRef":"5.2","requirement":"The product shall be implemented using programming languages, language features, and/or automation-enforced coding conventions that limit the introduction of memory safety vulnerabilities.\n\nExample: Via the use of memory safe languages, bounds checked container classes, restrictions on the use of raw pointers.","applicability":{},"assessment":{"accId":"ACC-MEM-KEV-3","reference":"The manufacturer shall use programming languages, language features, and/or automation-enforced coding conventions that limit the introduction of memory safety vulnerabilities.","objective":"The web browser's source code is hardened against the introduction of memory safety vulnerabilities.","preparation":"- Documentation describing the techniques the manufacturer uses to limit the introduction of memory safety vulnerabilities into the web browser.\n- Documentation describing how those methods are applied to the architectural components of the web browser.\n- For architectural components to which those methods are not applied, documentation describing the mitigations in place to reduce the risk of memory safety vulnerabilities from being successfully exploited.\n- Documentation describing the policies by which those methods are applied to the web browser's software development lifecycle.\n- Relevant software development lifecycle artefacts, such as design documents, bug tracker entries, security review outcomes.\n- The web browser's source code.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. For each of the methods used to limit the introduction of memory safety vulnerabilities, confirm via spot checks of the source code that the method is applied in accordance with the documentation.\n3. Confirm the relevant software development lifecycle policies are being followed via spot checks of artefacts.","verdict":"- **Pass**:\n    - The documentation describes methods that limit the introduction of memory safety vulnerabilities.\n    - The documentation maps those methods to the architectural components of the web browser.\n    - The mitigations applied to relevant architectural components convincingly reduce the risk of memory safety vulnerabilities from being successfully exploited.\n    - The relevant software development lifecycle policies are being followed.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation, source code, and artefact review.","guidance":""}}]},{"id":"5.3","clause":"5.3","title":"Secure by default configuration","overview":"Proposed ESR code SBD\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (b).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-TLS-SBD-1","clauseRef":"5.3","requirement":"The product shall be configured by default to reject TLS protocol versions, ciphers and configurations which present high risk to exploitation.\n\nEditor's note: \"high risk to exploitation\" is ok to say? and should we say \"reject or warn\" instead of \"reject\". See also REQ-TLS-CON-3.\n\nEditor's note: This requirement might be implied by Annex K. TODO: Research this interpretation and delete if redundant.","applicability":{},"assessment":{"accId":"ACC-TLS-SBD-1","reference":"The product shall be configured by default to reject TLS protocol versions, ciphers and configurations which present high risk to exploitation.","objective":"The product is configured by default to reject TLS protocol versions, ciphers and configurations which present high risk to exploitation.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Configure a web server to expose websites served with several protocol versions, ciphers or configurations which present a high risk to exploitation.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to each website and observe how it loads.","verdict":"- **Pass**: Each navigation attempt to the vulnerable website is blocked by the product.\n- **Fail**: Any of the above are not fulfilled.","evidence":"Logs or screenshots showing the product's response to the navigation.","guidance":""}},{"id":"REQ-TLS-SBD-2","clauseRef":"5.3","requirement":"The product shall be configured by default with an appropriate trusted root store based on the manufacturer's risk assessment and documented policy.","applicability":{},"applicabilityText":"Web browsers which maintain their own root store, rather than using the OS's root store.","assessment":{"accId":"ACC-TLS-SBD-2","reference":"The product shall be configured by default with an appropriate trusted root store based on the manufacturer's risk assessment and documented policy.","objective":"The product is configured by default with an appropriate trusted root store based on the manufacturer's risk assessment and documented policy.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Locate the technical documentation indicating the product's trusted root store policy.\n- Prepare a web server with TLS signed from a trusted root.","activities":"The following steps are to be carried out in order:\n\n1. Check that the trusted root policy exists\n2. Navigate to the website and observe the results","verdict":"- **Pass**:\n  - The trusted root policy exists\n  - Navigating to the trusted site succeeds\n- **Fail**: Any of the above are not fulfilled.","evidence":"Logs or screenshots showing the product's response to the navigation\nRoot store policy and listing of trusted roots","guidance":""}},{"id":"REQ-EXT-SBD-1","clauseRef":"5.3","requirement":"The product shall execute extensions with minimal privileges by default.\n\nExample: The extension execution process runs with no greater operating system privileges or capabilities than are required for the extension execution context.\n\nEditor's note: Could home in MAS? or IM?","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-SBD-1","reference":"The product shall execute extensions with minimal privileges by default.","objective":"Failure mode: extensions execute at full product privilege, or successfully invoke privileged browser or OS APIs.","preparation":"- A test extension declaring no permissions.\n- Tools for inspecting processes on the operating system.\n- Code executing privileged browser and OS APIs from inside the extension.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension\n2. Inspect the OS-level process the product runs the extension in, record privilege level\n3. Inspect the log of the extension's attempt to run privileged APIs","verdict":"- **Pass**:\n  - OS privilege level of the extension process is less than the product process.\n  - The extension invocation of privileged APIs failed.\n- **Fail**:\n  - OS privilege level of the extension process equals the product process, or the extension's invocation of privileged APIs succeeded.\n  - The extension escalates privilege at runtime via a privileged API not enumerated by activities.\n  - The extension is initially low-privilege but escalates after the inspection point.","evidence":"Process inspection log.\nExtension console log.","guidance":""}},{"id":"REQ-EXT-SBD-2","clauseRef":"5.3","requirement":"The product shall execute extensions in an isolated context.\n\nEditor's note: This covers the default configuration - the exploitation mitigation is covered in section 5.12.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-SBD-2","reference":"The product shall execute extensions in an isolated context.","objective":"Failure mode: an extension reads or modifies state belonging to the product, a loaded web page, or the operating system.","preparation":"- Product private state is selected, such as a unique string, or a configuration value.\n- A text file on the operating system, with test data.\n- A web page loaded in the product, with test data.\n- A test extension declaring no permissions, and executing attempts to read and modify state in the product, the loaded web page, and the operating system.\n- Console log access.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension\n2. Load a web page in the product","verdict":"- **Pass**:\n  - Product private state data access was denied.\n  - File system text file access was denied.\n  - Web page test data access was denied.\n- **Fail**:\n  - Cross-context state access was possible in the product, the loaded web page, or the operating system.","evidence":"Console log output from the test extension demonstrated state access or denial.","guidance":""}},{"id":"REQ-PWR-SBD-1","clauseRef":"5.3","requirement":"The product's technical documentation shall describe all web platform APIs it implements that fall under the definition of a Powerful Web Platform Feature, detailing the specific APIs and the mechanism by which express user permission is obtained before they can be used by a website.","applicability":{},"assessment":{"accId":"ACC-PWR-SBD-1","reference":"The product's technical documentation shall describe all web platform APIs it implements that fall under the definition of a Powerful Web Platform Feature, detailing the specific APIs and the mechanism by which express user permission is obtained before they can be used by a website.","objective":"The Powerful Web Platform Features supported by the product are documented.","preparation":"- The product's technical documentation.","activities":"-  Review the documentation.","verdict":"- **Pass**:\n\n    - The product's technical documentation correctly lists the Powerful Web Platform Features supported by the product.\n    - For each Powerful Web Platform Feature listed, the mechanism by which express user permission is obtained is detailed.\n\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation review.","guidance":""}},{"id":"REQ-PWR-SBD-2","clauseRef":"5.3","requirement":"The product shall provide a mechanism for users to select the default behaviour when a web page wishes to use a given Powerful Web Platform Feature, which shall at least include denying by default.","applicability":{},"assessment":{"accId":"ACC-PWR-SBD-2","reference":"The product shall provide a mechanism for users to select the default behaviour when a web page wishes to use a given Powerful Web Platform Feature, which shall at least include denying by default.","objective":"The product provides a mechanism for users to configure default behaviour when a web page requests to use a Powerful Web Platform Feature.","preparation":"- The product installed from scratch, or reset to its default settings.\n- Test web page or pages that exercises every Powerful Web Platform Feature identified in the product's technical documentation.","activities":"The following steps are to be carried out in order:\n\n1. Locate the product's UI that allows configuring the default behaviour of individual Powerful Web Platform Features.\n2. Verify the existence of options to deny or block access by default to every Powerful Web Platform Features supported by the product.\n3. For each Powerful Web Platform Feature, set the default behaviour to block or deny.\n3. Navigate to the test web page or pages and trigger the request to access every Powerful Web Platform Feature.","verdict":"- **Pass**:\n    - The product settings provide an option to individually deny access to all supported Powerful Web Platform Features by default.\n    - Applying the setting automatically blocks the test web page's access to Powerful Web Platform Features without presenting a permission prompt to the user.\n- **Fail**:\n    - The deny-by-default option does not exist.\n    - Any Powerful Web Platform Feature is still accessible, or still prompts the user despite the deny-by-default setting being applied.","evidence":"Screenshots of the settings UI presenting the option.\nConsole logs and/or UI captures from the test web page showing the denied request.","guidance":""}}]},{"id":"5.4","clause":"5.4","title":"Secure Updates","overview":"Proposed ESR code: SU\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (c).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-TLS-SU-1","clauseRef":"5.4","requirement":"The product's root store shall be kept up to date appropriately, based on the manufacturer's risk assessment and documented policy.","applicability":{},"applicabilityText":"Web browsers which maintain their own root store, rather than using the OS's root store.","assessment":{"accId":"ACC-TLS-SU-1","reference":"The product's root store shall be kept up to date appropriately, based on the manufacturer's risk assessment and documented policy.","objective":"The product's root store is kept up to date in accordance with the documented policy.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Locate the documented policy describing how and when the trusted root store is updated.\n- Capture the initial trusted root store contents.","activities":"The following steps are to be carried out in order:\n\n1. Exercise the documented root store update mechanism (e.g., product update, separate channel).\n2. Capture the trusted root store contents after the update.\n3. Compare the change against the documented policy.","verdict":"- **Pass**:\n    - The documented update mechanism functions as documented\n    - The resulting change to the root store is consistent with the documented policy.\n- **Fail**: Either of the above are not fulfilled.","evidence":"Documented root store update policy.\nList of trusted roots before and after the update.","guidance":""}},{"id":"REQ-EXT-SU-1","clauseRef":"5.4","requirement":"The product shall support automatic updates of extensions, and before installing an update shall cryptographically verify the update.","applicability":{},"applicabilityText":"Extensions installed via the product's extension distribution channel. Extensions installed by enterprise policy, by the developer as unpacked extensions, or sideloaded directly by the user are out of scope of this requirement.\n\nPer clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-SU-1","reference":"The product shall support automatic updates of extensions, and before installing an update shall cryptographically verify the update. Applicability: Extensions installed via the product's extension distribution channel. Extensions installed by enterprise policy, by the developer as unpacked extensions, or sideloaded directly by the user are out of scope of this requirement.","objective":"The product supports automated updates of extensions, and cryptographically verifies extension updates prior to installation.","preparation":"- A correctly signed test extension installed via the product's extension distribution channel.\n- Update variations of the test extension: signed correctly, signed incorrectly, unsigned, and malformed.\n- A test extension update server.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension.\n2. Configure the update server with an update variation.\n3. Perform update per product documentation.\n4. Repeat steps 2-3 with each variation.","verdict":"- **Pass**:\n  - Correctly signed update is installed.\n  - All other variations are not installed.\n- **Fail**: Any of the above are not fulfilled.","evidence":"Product user interface per the documentation, showing the update status for an extension.","guidance":""}},{"id":"REQ-STORE-SU-1","clauseRef":"5.4","requirement":"The product shall maintain the validity of data stored to disk across updates.","applicability":{},"assessment":{"accId":"ACC-STORE-SU-1","reference":"The product shall maintain the validity of data stored to disk across updates.","objective":"Assess whether the product maintains the validity of data stored to disk across updates.","preparation":"- Reset browser to factory default settings.\n    - Prepare tooling to initiate an update.\n    - Prepare tooling that will provide visibility into data stored in the browser.\n    - Load data into browser to cover available storage mechanisms, including LocalStorage, Cookie storage and IndexedDB.","activities":"1. Making use of tooling, verify the data that has been added to storage.\n    2. Perform the update of the browser.\n    3. Verify whether the data is available in storage after the update.","verdict":"- **Pass**:\n        - The data is available prior to browser update.\n        - The data available subsequent to browser update is identical.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling to demonstrate each verdict","guidance":""}},{"id":"REQ-STORE-SU-2","clauseRef":"5.4","requirement":"The product shall update the Public Suffix List regularly.","applicability":{},"assessment":{"accId":"ACC-STORE-SU-2","reference":"The product shall update the Public Suffix List regularly.","objective":"Assess whether the product updates the public suffix list regularly.","preparation":"- Technical documentation containing public suffix list update policy.\n    - Browser with out-of-date public suffix list, with known missing suffix.\n    - Identify methodology or tooling to test Public Suffix List entries, e.g.\n        - Set a cookie at the PSL level, or\n        - Tooling to inspect and output PSL.","activities":"1. Verify state of the missing PSL suffix.\n    2. Await update according to policy.\n    3. Verify the updated state of the missing PSL suffix.","verdict":"- **Pass**:\n        - Testing initially shows known-missing entry as not present in internal list of eTLDs.\n        - After update period, testing shows known-missing entry is present in internal list of eTLDs.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling to demonstrate each verdict","guidance":""}}]},{"id":"5.5","clause":"5.5","title":"Authentication and access control","overview":"Proposed ESR code: AAC\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (d).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-EXT-AAC-1","clauseRef":"5.5","requirement":"The product shall enforce a granular permission model for the extension.\n\nExample: Permissions are decomposed into capability groupings rather than a single all-or-nothing grant.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AAC-1","reference":"The product shall enforce a granular permission model for the extension.","objective":"An extension receives the capabilities it requests but no more, and in capability-specific granularity.","preparation":"- Documentation of extension capabilities, and test extensions declaring each declaring a permission and exercising it, for a random sample of available capabilities.","activities":"The following steps are to be carried out in order:\n\n1. Install extension, and execute the capability\n2. Repeat for each extension","verdict":"- **Pass**:\n  - Exercise of the capability in the extension was confirmed.\n- **Fail**:\n  - The extension was not able to exercise the capability.","evidence":"Product user interface per supplied documentation.\nConsole logs of extension execution.","guidance":""}},{"id":"REQ-EXT-AAC-2","clauseRef":"5.5","requirement":"The product shall grant an extension only the permissions declared in its manifest and granted in accordance with the product's permission model.\n\nNote: Some permissions are considered low-impact and auto-granted without an explicit user-visible prompt. The user-prompt requirement is covered separately by REQ-EXT-AAC-3.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AAC-2","reference":"The product shall grant an extension only the permissions declared in its manifest and granted in accordance with the product's permission model.","objective":"Failure mode: an extension exercises a capability without manifest declaration, or beyond what the permission model grants (manifest/model bypass).","preparation":"- Product documentation of the permission model, identifying which permissions are auto-granted and which require an explicit user grant.\n- Test extension A: declares one auto-granted permission and one user-grant permission, with code exercising both, instrumented to log access.\n- Test extension B: declares the user-grant permission, with code exercising it, instrumented.\n- Test extension C: does not declare the user-grant permission but contains code attempting to exercise it, instrumented.","activities":"The following steps are to be carried out in order:\n\n1. Install extension A, completing the product's normal install flow including any user-grant step for the declared permission.\n2. Install extension B, and at the user-grant step, decline.\n3. Install extension C.\n4. For each installed extension, exercise the instrumented code and record which capabilities were reached.","verdict":"- **Pass**:\n  - Extension A exercises both the auto-granted and the user-granted capabilities.\n  - Extension B cannot exercise the capability for which the user declined the grant.\n  - Extension C cannot exercise the undeclared capability.\n- **Fail**:\n  - An extension exercises a capability not declared in its manifest.\n  - An extension exercises a capability the permission model did not grant.\n  - The product surfaces an auto-grant for a permission not declared in the manifest.","evidence":"Extension console logs and test extension instrumentation.\nProduct permission-model documentation referenced for the auto-grant / user-grant classification.","guidance":""}},{"id":"REQ-EXT-AAC-3","clauseRef":"5.5","requirement":"The product shall prompt the user with the manifest-declared permissions prior to installation, listing the capabilities and implications of each permission, and allow the user to approve or decline the installation.","applicability":{},"applicabilityText":"Extensions installed via the product's extension distribution channel. Extensions installed by enterprise policy, by the developer as unpacked extensions, or sideloaded directly by the user are out of scope of this requirement.\n\nPer clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AAC-3","reference":"The product shall prompt the user with the manifest-declared permissions prior to installation, listing the capabilities and implications of each permission, and allow the user to approve or decline the installation. Applicability: Extensions installed via the product's extension distribution channel. Extensions installed by enterprise policy, by the developer as unpacked extensions, or sideloaded directly by the user are out of scope of this requirement.","objective":"Failure mode: granted capabilities do not match the user's approve-or-decline decision; for example, a capability is available after the user declined.","preparation":"- Test extension with declared permissions and exercising code instrumented to log access to capability of the permission being tested.","activities":"The following steps are to be carried out in order:\n\n1. Install test extension\n2. Capture user interface, confirm declared permissions are visibly prompted\n3. Accept, and confirm\n4. Repeat process for second extension, but decline","verdict":"- **Pass**:\n  - In both cases, the permissions requested and clearly visible and the user is presented with a decision to grant or decline.\n  - In the approve case, the extension is able to exercise the capability.\n  - In the decline case, the extension cannot exercise the capability.\n- **Fail**:\n  - The resulting capability access by the extension does not match what was granted by the user.\n  - The user dismisses the prompt without an explicit choice and the install proceeds with a default outcome.\n  - The prompt appears after install has begun.","evidence":"User interface captures.\nExtension console logs.","guidance":""}},{"id":"REQ-EXT-AAC-4","clauseRef":"5.5","requirement":"The product shall allow the user to review and revoke extension access to specific origins after installation.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AAC-4","reference":"The product shall allow the user to review and revoke extension access to specific origins after installation.","objective":"Failure mode: an extension retains origin access after the user revokes it (revocation bypass).","preparation":"- Test extension with declared and approved access to one or more websites.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension, approving access to the requested sites\n2. After install, view the extension permissions user interface\n3. Use the extension to access the origin\n4. If the origin requested is listed, revoke it\n5. Use the extension to access the origin","verdict":"- **Pass**:\n  - The extension install user interface shows the correct origin.\n  - The extension permissions user interface shows the correct origin.\n  - The extension is able to access the origin when granted, or not when declined.\n  - Origin access is revocable in the extension management user interface.\n  - After revocation, the extension can no longer access the origin.\n- **Fail**:\n  - After revocation, the extension can still access the origin.\n  - Revocation is reported in the UI but takes effect only after browser restart.\n  - Active sessions and in-flight requests retain access despite revocation.","evidence":"Product user interface for extension install and management.\nExtension console log.","guidance":""}},{"id":"REQ-EXT-AAC-5","clauseRef":"5.5","requirement":"The product shall ensure isolation between the execution and data contexts of different extensions.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AAC-5","reference":"The product shall ensure isolation between the execution and data contexts of different extensions.","objective":"Failure mode: one extension reads another extension's data or invokes its functions (cross-extension breach).","preparation":"- Install two test extensions.\n- The first writes data to storage and implements a background function.\n- The other attempts to access the data and call the function.","activities":"The following steps are to be carried out in order:\n\n1. Install both extensions\n2. Validate that the first extension wrote its data and that its function loaded\n3. Attempt to read the storage and invoke the function from the other extension","verdict":"- **Pass**:\n  - The second extension cannot access the data or invoke the function of the first.\n- **Fail**:\n  - The second extension can access the data or invoke the function of the first.","evidence":"Extension console log.","guidance":""}},{"id":"REQ-STORE-ACC-1","clauseRef":"5.5","requirement":"The product shall store data and enforce access according to the Same Origin Policy.","applicability":{},"assessment":{"accId":"ACC-STORE-AAC-1","reference":"The product shall store data and enforce access according to the Same Origin Policy.","objective":"Assess whether the product presents stores and enforces access according to Same Origin Policy.","preparation":"- Prepare tooling that will provide visibility into data available for a given context.\n    - Website hosted on origin A, that will provide storage data.\n    - Website hosted on origin B, that will provide storage data.\n    - Reset browser to factory default settings.","activities":"1. Navigate to the website on origin A.\n    2. Making use of tooling, verify the data is added to storage, and is available in the context.\n    3. Navigate to the website on origin B.\n    4. Verify that the data set when accessing the first site is unavailable in the new context.\n    5. Verify that the data set when accessing the second site is available in the new context.\n    6. Navigate back to the website on origin A.\n    7. Verify that the data set by the site is still available.","verdict":"- **Pass**:\n        - When site adds data to storage it is available.\n        - When the site looks for data, it does not see data from the other origin\n        - When the second site sets data it is also available.\n        - When navigating back to the first site, the data set when visiting initially will still be available.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling to demonstrate each verdict","guidance":""}},{"id":"REQ-STORE-ACC-2","clauseRef":"5.5","requirement":"The product shall not share or make data available across browser profiles.","applicability":{},"assessment":{"accId":"ACC-STORE-AAC-2","reference":"The product shall not share or make data available across browser profiles.","objective":"Assess whether the product enforces separation of data across browser profiles.","preparation":"- Identify a relevant website that can be used to set uniquely identifiable data.\n    - Prepare tooling that will provide visibility into data available for a given browser profile.\n    - Identify supported browser profiles (eg private browsing, user profiles etc).\n    - Reset browser to factory default settings.\n    - Prepare browser configuration to support available browser profiles.","activities":"1. Open the website in the default browser profile, and note the data set by the website.\n    2. Open the website in each other browser profile, and note the data available in each profile.\n    3. Using the default browser profile, reload the website and note the data available.","verdict":"- **Pass**\n        - The data gets set in the default browser profile when visiting the website.\n        - For each browser profile available, the data is set by the browser profile context successfully.\n        - The data set in the default browser profile is not available in any other browser profile.\n        - Upon returning to the website, the data set initially is still available, and data set in individual profiles are not available.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling to demonstrate each verdict","guidance":""}},{"id":"REQ-STORE-ACC-3","clauseRef":"5.5","requirement":"The product shall enforce Same Origin Policy access control for storage data outside rendering processes.","applicability":{},"assessment":null},{"id":"REQ-SOP-AAC-1","clauseRef":"5.5","requirement":"The product shall deny access in one origin to all parts of another origin, except as defined in the user documentation.\n\nExample: Web pages may load images from other origins, message using `window.postMessage` and may access limited properties such as `Location`. Web pages may not access the document object model or global Window scope from scripts of other origins. The user documentation references industry standards with implementation recommendations and additinal examples.","applicability":{},"assessment":null},{"id":"REQ-SOP-AAC-2","clauseRef":"5.5","requirement":"The product shall isolate origin-specific data such as cookies, Web Storage, IndexedDB and any other storage, ensuring it's not available to any other origin, except through protocol-determined methods.\n\nEditor's note: is this limited to top-level pages?\n\nEditor's note: are cookies awkward here? in what way?\n\nEditor's note: need to add examples for cross domain storage access is allowed, etc.","applicability":{},"assessment":null},{"id":"REQ-PWR-AAC-1","clauseRef":"5.5","requirement":"The product shall require express user permission before allowing a web page to use Powerful Web Platform Features.","applicability":{},"assessment":{"accId":"ACC-PWR-AAC-1","reference":"The product shall require express user permission before allowing a web page to use Powerful Web Platform Features.","objective":"The product does not allow web pages to access Powerful Web Platform Features without express user permission.","preparation":"- The product installed from scratch, or reset to its default settings.\n- Test web page or pages that exercises every Powerful Web Platform Feature identified in the product's technical documentation.","activities":"- For every Powerful Web Platform Feature identified in the product's technical documentation:\n\t- Navigate to the test web page.\n    - Verify via the web page's behaviour and/or console log that the Powerful Web Platform Feature is not available to the web page.\n    - Trigger the script to request the Powerful Web Platform Feature.\n    - Take whatever action is necessary to allow the web page access to the Powerful Web Platform Feature.\n    - Verify via the web page's behaviour and/or console log that the Powerful Web Platform Feature is now available to the web page.","verdict":"- **Pass**:\n    - The web page does not receive access to Powerful Web Platform Features unless the user has taken an action to explicitly approve.\n- **Fail**:\n    - The above is not fulfilled.","evidence":"Screenshots of the UI allowing the user to give express permission to access the Powerful Web Platform Feature.\nConsole logs and/or UI captures from the test web page showing no access was possible prior to user approval.\nConsole logs and/or UI captures from the test web page showing access was possible after user approval.","guidance":""}}]},{"id":"5.6","clause":"5.6","title":"Confidentiality","overview":"Proposed ESR code: CON\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (e).\n\nIn this clause, reference can be made to the Annex K (normative), specifying State Of The Art Cryptography","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-TLS-CON-1","clauseRef":"5.6","requirement":"The product shall support TLS versions and configurations indicated as \"recommended\" (R) of the ENISA Agreed Cryptographic Methods [1], and it may support TLS versions and configurations indicated as \"legacy\" (L).\n\nNote: These algorithms are listed on page 37-38 of [1](https://certification.enisa.europa.eu/document/download/a845662b-aee0-484e-9191-890c4cfa7aaa_en?filename=ECCG%20Agreed%20Cryptographic%20Mechanisms%20version%202.pdf). TLS 1.3 [i.7] is R, and TLS 1.2 [i.6] is L. The L[2025] algorithms (with CBC) are not considered state of the art, and should be ignored.\n\nEditor's note: This requirement might be implied by Annex K. TODO: Research this interpretation and delete if redundant.","applicability":{},"assessment":{"accId":"ACC-TLS-CON-1","reference":"The product shall support TLS versions and configurations indicated as \"recommended\" (R) of the ENISA Agreed Cryptographic Methods [1], and it may support TLS versions and configurations indicated as \"legacy\" (L).","objective":"The product supports all TLS versions and configurations marked as recommended by ENISA Agreed Cryptographic Methods.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Identify the current list of recommended TLS versions and configurations from ENISA Agreed Cryptographic Methods [1].\n- Configure web servers, each serving content under a distinct recommended TLS version/configuration.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to each test server and record whether the connection succeeds.","verdict":"- **Pass**: Each recommended TLS version/configuration is reachable from the product.\n- **Fail**: The pass condition is not fulfilled.","evidence":"Logs or screenshots of each navigation result.\nReference list of ENISA recommended TLS versions/configurations used.","guidance":""}},{"id":"REQ-TLS-CON-2","clauseRef":"5.6","requirement":"The web browser shall check the full validity of certificate chain through to the root, including for expiration.","applicability":{},"assessment":{"accId":"ACC-TLS-CON-2","reference":"The product shall check the full validity of certificate chain through to the root, including for expiration and revocation.","objective":"The product validates the full certificate chain through to the root, including expiration and revocation.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Configure a baseline web server with a valid TLS certificate chained to a trusted root.\n- Configure additional web servers with: an expired certificate, a revoked certificate, a certificate chained to a root not in the product's trusted root store, and an incomplete chain.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to the baseline server and record the result.\n2. Navigate to each defective-chain server and record the result.","verdict":"- **Pass**:\n  - The baseline server is reachable.\n  - For each defective-chain server, the product's response visibly differs from the baseline (e.g., blocked, warned, error).\n- **Fail**: Either of the above is not fulfilled.","evidence":"Logs or screenshots of each navigation result.\nCertificate details for each test server.","guidance":""}},{"id":"REQ-TLS-CON-3","clauseRef":"5.6","requirement":"The product shall warn or obstruct the user from interacting with content served over insecure connections, including expired certificates and insecure TLS configurations.\n\nExample: When presenting content served with cryptographic methods with a certain risk of exploitation, a web browser presents a user with a user interface element representing a broken lock, or an interstitial requiring user interaction to proceed.","applicability":{},"assessment":{"accId":"ACC-TLS-CON-3","reference":"The product shall warn or obstruct the user from interacting with content served over insecure connections, including expired certificates and insecure TLS configurations.","objective":"The product warns or obstructs the user from interacting with content served over insecure connections.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Configure web servers, each serving content over an insecure variant: an expired certificate, a certificate chained to an untrusted root, and an insecure TLS configuration such as a deprecated protocol version or weak cipher.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to each test server.\n2. Record the product's UI response and whether content interaction is permitted, with or without an explicit user override.","verdict":"- **Pass**: For each insecure variant, the product presents a warning UI or obstructs interaction with the content.\n- **Fail**: The pass condition is not fulfilled.","evidence":"Screenshots or recordings of the warning/obstruction UI for each variant.","guidance":""}},{"id":"REQ-TLS-CON-4","clauseRef":"5.6","requirement":"The product shall implement appropriate technologies to promote or require the use of HTTPS rather than HTTP.\n\nExample: Implementation of HSTS [i.8], active mixed content blocking [i.9], and HTTPS-First loading strategies.","applicability":{},"assessment":{"accId":"ACC-TLS-CON-4","reference":"The product shall implement appropriate technologies to promote or require the use of HTTPS rather than HTTP.","objective":"The product implements one or more technologies that promote or require HTTPS over HTTP.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Configure web servers serving the same content over HTTP and over HTTPS.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to the HTTP variant and observe whether the product upgrades to HTTPS, warns, or blocks.\n2. Load an HTTPS page that includes HTTP subresources and observe mixed-content handling.","verdict":"- **Pass**: The product applies at least one technology that promotes or requires HTTPS, such as HSTS, HTTPS-First mode, automatic HTTP-to-HTTPS upgrade, or mixed-content blocking.\n- **Fail**: The pass condition is not fulfilled.","evidence":"Logs or screenshots of HTTP vs HTTPS navigation behaviour.","guidance":""}},{"id":"REQ-TLS-CON-6","clauseRef":"5.6","requirement":"The web browser shall have a mechanism to respond to the revocation or loss of trust of CA certificates.","applicability":{},"assessment":null},{"id":"REQ-EXT-CON-1","clauseRef":"5.6","requirement":"The product shall prevent secrets stored by extensions from being read by other extensions or by web content.\n\nNOTE: This requirement addresses the platform-enforced isolation boundary between extensions, and between extensions and web content. It does not address application-level leaks within an extension's own code.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-CON-1","reference":"The product shall prevent secrets stored by extensions from being read by other extensions or by web content.","objective":"Failure mode: secrets stored by one extension are readable by other extensions or by web content (secret disclosure).","preparation":"- A test extension stores a secret.\n- Another test extension and a test web page attempt to read it.","activities":"The following steps are to be carried out in order:\n\n1. Install both test extensions and open test web page in a tab.\n2. Verify the test extension stored the secret.\n3. Use the second extension to attempt to read the stored secret via every extension API that can access storage.\n4. Use the test web page to attempt to read the stored secret via every storage API available to web pages.","verdict":"- **Pass**:\n  - The stored secret can't be read from the reader extension or from the web page.\n- **Fail**:\n  - The stored secret can be read from the reader extension or from the web page.","evidence":"Console log from extension and from the web page.","guidance":""}},{"id":"REQ-STORE-CON-1","clauseRef":"5.6","requirement":"The product shall not send third-party cookies by default. They may be supported consistent with the `Partitioned` attribute.\n\nNOTE: The product can provide users the ability to share third-party cookies, whether on a case-by-case basis through interaction as in Storage Access API or throughout their browser profile through configuration.","applicability":{},"assessment":{"accId":"ACC-STORE-CON-1","reference":"The product shall not send third-party cookies by default. They may be supported consistent with the `Partitioned` attribute.","objective":"Assess that third-party cookies are not sent by default.","preparation":"- Reset browser to factory default settings.\n    - Prepare tooling to view browser http requests.\n    - Prepare tooling to view stored cookies.\n    - Website hosted on site A, that provides cookies.\n    - Website hosted on site B, with :\n      - embedded resources from site A,\n      - iframe from site A that sets a `Partitioned` cookie, and\n      - iframe from site A that sets a cookie without the `Partitioned` keyword.","activities":"1. Visit website on site A, and verify the cookies that have been set.\n    2. Visit website on site B, and verify whether the cookies are sent to site A when loading resources.\n    3. Verify whether either of the cookies from site A iframes embedded on site B are stored.\n    4. Reload website on site B, and verify the cookies sent to site A when loading resources.\n    5. Visit website on site A, and verify whether the cookies sent.","verdict":"- **Pass**:\n        - The cookies are set successfully for site A.\n        - The cookies are not sent to site A, when loading site B.\n        - The cookie set within an iframe without a `Partitioned` keyword is not stored.\n        - The cookie set within an iframe with a `Partitioned` keyword can be stored.\n        - On reloading the site, cookies from site A are not sent to site B.\n        - If the `Partitioned` keyword cookie was stored, it can be sent to the site A iframes and resources within site B.\n        - When re-visiting the website on site A, the cookies only cookies sent are those set directly visiting that site.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling showing request data to demonstrate each verdict.\nScreenshot(s) or log output from tooling showing cookie storage state to demonstrate each verdict.","guidance":""}},{"id":"REQ-STORE-CON-2","clauseRef":"5.6","requirement":"The product shall make use of OS access control, encryption methods or other mechanisms to ensure confidentiality of disk-stored data.","applicability":{},"assessment":{"accId":"ACC-STORE-CON-2","reference":"The product shall make use of OS access control, encryption methods or other mechanisms to ensure confidentiality of disk-stored data.","objective":"Assess that OS access control, encryption methods and other mechanisims are used to ensure confidentiality of disk-stored data.","preparation":"- Access to product source code.\n    - Access to OS documentation.","activities":"- Identify available access control methods for OS.\n    - Identify data written to disk by product.\n    - Verify that the data stored uses appropriate access control mechanisms.","verdict":"- **Pass**: Each instance of data written to disk is using appropriate access control.\n    - **Fail**: The above is not fulfilled.","evidence":"List of disk-stored data from product.\nCorresponding list of OS access control mechanisms used and justification for why each is appropriate.","guidance":""}},{"id":"REQ-STORE-CON-3","clauseRef":"5.6","requirement":"The product shall store browser cache data such that they are keyed to both top-level site and resource.","applicability":{},"assessment":{"accId":"ACC-STORE-CON-3","reference":"The product shall store browser cache data such that they are keyed to both top-level site and resource.","objective":"Assess that browser storage cache data is keyed to both top-level site and resource.","preparation":"- Website hosted on site A, including resource A from site C.\n    - Website hosted on site B, including resource A from site C.\n    - Tooling to inspect browser cache.\n    - Tooling to inspect request data.\n    - Reset browser to factory default settings.","activities":"1. Visit the website hosted on site A and inspect browser cache.\n    2. Visit the website hosted on site B, verify request data and inspect browser cache.","verdict":"- **Pass**:\n        - If resource A from site C is stored in browser cache, it should keyed to site A.\n        - Request data from site B should include resource A from site C. It should not have been retrieved from cache.\n        - If resource A from site C is stored in browser cache, it may be stored twice, and can be keyed against both site A and site B.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling showing browser cache content to demonstrate each verdict.\nScreenshot(s) or log output from tooling showing request and response for resource A, when visiting site B, to demonstrate the corresponding verdict.","guidance":""}},{"id":"REQ-SOP-CON-1","clauseRef":"5.6","requirement":"The product shall only allow scripts to access the body of a cross-origin HTTP response where the source origin has opted to allow access by the requesting origin.\n\nExample: Implementation of Cross-Origin Resource Sharing (CORS)","applicability":{},"assessment":null},{"id":"REQ-SOP-CON-2","clauseRef":"5.6","requirement":"Where the product allows cross-origin embedding of a resource in documents, the product shall limit information about that resource as specified in the technical documentation.\n\nExample: Cross-origin embedding of the height and width of an image are exposed to scripts, while the contents of the image are not exposed unless CORS is enabled by the source origin of the image.\n\nEditor's note: In principle, CON-1 might imply CON-2, and maybe we could put this all in assessment steps. Or maybe better to be explicit?","applicability":{},"assessment":null}]},{"id":"5.7","clause":"5.7","title":"Integrity","overview":"Proposed ESR code: INT\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (f).\n\nNote: TLS-related clauses contribute to integrity.","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-EXT-INT-1","clauseRef":"5.7","requirement":"The product shall cryptographically verify extensions before installation and update.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-INT-1","reference":"The product shall cryptographically verify extensions before installation and update.","objective":"The product cryptographically verifies an extension before installation and before update.","preparation":"- Four test extensions, signed correctly, incorrectly, unsigned, and malformed.\n- Four more test extension, each an update of the correctly signed extension, and these four each of signed correctly, signed incorrectly, unsigned, and malformed.\n- A test extension update server.","activities":"The following steps are to be carried out in order:\n\n1. Attempt installation of each variation, recording the result.\n2. For the correctly signed extension, attempt update with each variation, recording the result.","verdict":"- **Pass**:\n  - The correctly signed extension is installed, all others are rejected by the product.\n  - Only the correctly signed update is installed, all others are rejected by the product.\n- **Fail**: Any of the above are not fulfilled.","evidence":"Extension console logs.\nProduct user interface captures.","guidance":""}},{"id":"REQ-PWR-INT-1","clauseRef":"5.7","requirement":"The product shall protect permission prompts against manipulation by the web page.","applicability":{},"assessment":{"accId":"ACC-PWR-INT-1","reference":"The product shall protect permission prompts against manipulation by the web page.","objective":"Permission prompts cannot be obscured, modified, or approved by web pages.","preparation":"- The product installed from scratch, or reset to its default settings.\n- A test web page that uses a Powerful Web Platform Feature and attempts to manipulate the product's permission prompt. For example by utilizing CSS z-index overlays, transparent iframes, DOM manipulation etc.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to the test web page.\n2. Trigger the script to request access to the Powerful Web Platform Feature.","verdict":"- **Pass**:\n    - Any permission prompt is unable to be obscured or manipulated by the test web page.\n- **Fail**:\n    - The above is not fulfilled.","evidence":"Screenshot of the permission prompt or other UI surface.","guidance":""}},{"id":"REQ-PWR-INT-2","clauseRef":"5.7","requirement":"The product shall only enable Powerful Web Platform Features for use within Secure Contexts.","applicability":{},"assessment":{"accId":"ACC-PWR-INT-2","reference":"The product shall only enable Powerful Web Platform Features for use within Secure Contexts.","objective":"Web pages accessed via non-secure contexts are unable to use Powerful Web Platform Features.","preparation":"- The product installed from scratch, or reset to its default settings.\n- Test web page or pages that exercises every Powerful Web Platform Feature identified in the product's technical documentation in a non-secure context.","activities":"The following steps are to be carried out in order:\n\n- For every Powerful Web Platform Feature identified in the product's technical documentation:\n    - Navigate to the test web page.\n    - Trigger the script to request the Powerful Web Platform Feature.\n    - Verify via the web page's behaviour and/or console log that the Powerful Web Platform Feature is not available to the web page.","verdict":"- **Pass**:\n    - The user is not prompted to grant access to any Powerful Web Platform Feature.\n    - The web page does not receive access to any Powerful Web Platform Feature.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Console logs and/or UI captures from the test web page showing no access to the Powerful Web Platform Features.","guidance":""}}]},{"id":"5.8","clause":"5.8","title":"Data Minimisation","overview":"Proposed ESR code: DM\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (g).\n\nNote: TLS-related clauses contribute to data minimization.","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-PWR-DM-1","clauseRef":"5.8","requirement":"Powerful Web Platform Feature permissions shall be origin-scoped by default, with broader scoping permitted only via express user action, or opt-in by the origins.","applicability":{},"assessment":{"accId":"ACC-PWR-DM-1","reference":"Powerful Web Platform Feature permissions shall be origin-scoped by default, with broader scoping permitted only via express user action, or opt-in by the origins.","objective":"A permission granted to one origin is not automatically inherited by a different origin without explicit intent.","preparation":"- The product installed from scratch, or reset to its default settings.\n- Two test web pages hosted on distinct origin (Origin A and Origin B), that both request the same Powerful Web Platform Feature.\n- Two test web pages hosted on distinct sites (Site A and Site B), that both request the same Powerful Web Platform Feature.","activities":"The following steps are to be carried out in order:\n\n1. Load Origin A, trigger the request, and explicitly grant the permission.\n2. Verify Origin A has access.\n3. Load Origin B and attempt to access the Powerful Web Platform Feature.\n4. Load Site A, trigger the request, and explicitly grant the permission.\n5. Verify Site A has access.\n6. Load Site B and attempt to access the Powerful Web Platform Feature.","verdict":"- **Pass**:\n    - Origin B does not inherit the permission and must prompt the user independently or fail automatically.\n    - Site B does not inherit the permission and must prompt the user independently or fail automatically.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Console logs and/or UI captures from the test web page showing access to the Powerful Web Platform Features has been granted to the test page on Origin A.\nConsole logs and/or UI captures from the test web page showing no access to the Powerful Web Platform Features to the test page on Origin B.","guidance":""}},{"id":"REQ-PWR-DM-2","clauseRef":"5.8","requirement":"Powerful Web Platform Feature permissions decisions shall apply to each Browser Profile separately.","applicability":{},"assessment":{"accId":"ACC-PWR-DM-2","reference":"Powerful Web Platform Feature permissions decisions shall apply to each Browser Profile separately.","objective":"A permission granted or denied in one Browser Profile does not extend to another Browser Profile.","preparation":"- The product installed from scratch, or reset to its default settings and configured with two distinct Browser Profiles (e.g., Profile A and Profile B).\n- A test web page that uses a Powerful Web Platform Feature.","activities":"The following steps are to be carried out in order:\n\n1. Load the test site in Profile A, trigger the request, and explicitly grant the permission.\n2. Load the test site in Profile B and attempt to access the Powerful Web Platform Feature.","verdict":"- **Pass**:\n    - The permission state in Profile B is unaffected by Profile A, and the product does not provide access to the Powerful Web Platform Feature on step 2 of the assessment activities without express user permission.\n- **Fail**:\n    - The above is not fulfilled.","evidence":"Console logs and/or UI captures from the test web page showing access to the Powerful Web Platform Features has been granted to the test page in Profile A.\nConsole logs and/or UI captures from the test web page showing no access to the Powerful Web Platform Features to the test page in Profile B.","guidance":""}}]},{"id":"5.9","clause":"5.9","title":"Availability Protection","overview":"Proposed ESR code: AP\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (h).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-AP-1","clauseRef":"5.9","requirement":"The web browser shall take steps to reduce the risk that errors or crashes in one website running in one tab cause other, unrelated tabs to crash.\n\nExample: Running different tabs in different renderer processes some of the time\n\nNote: Guarantees here are not absolute. Current web browsers have various cases where one tab can take another down.","applicability":{"UC-CONS":"required","UC-INST":"required","UC-ETAB":"not-required"},"applicabilityText":"UC-CONS and UC-INST","assessment":null},{"id":"REQ-AP-2","clauseRef":"5.9","requirement":"The web browser shall take steps, on a best-effort basis, to save the state of running websites such that they can be restored later following an incident.","applicability":{"UC-CONS":"required","UC-INST":"required","UC-ETAB":"not-required"},"applicabilityText":"UC-CONS and UC-INST","assessment":null},{"id":"REQ-EXT-AP-1","clauseRef":"5.9","requirement":"The product shall make the best effort to prevent the ability of an extension to make the product unavailable.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-AP-1","reference":"The product shall make the best effort to prevent the ability of an extension to make the product unavailable.","objective":"The product makes a best-effort attempt to prevent extensions from making the product unavailable.","preparation":"- Test extensions, one with a hot CPU loop, one with unbounded memory allocation, and one with a crash if possible.\n- Tools for process inspection.\n- Product documentation.","activities":"The following steps are to be carried out in order:\n\n1. Install a test extension\n2. Try opening a new tab, opening a web page\n3. Try disabling the extension\n4. Repeat for each extension","verdict":"- **Pass**: At least one of the following holds:\n  - Product can open a new tab, navigate to a website, and disable the extension under the resource conditions caused by the extension.\n  - Has documentation explaining the best effort made.\n- **Fail**:\n  - The product is unresponsive (user cannot open a new tab, navigate, or disable the extension) AND no mitigating approach is documented.","evidence":"Process logs.\nProduct documentation","guidance":""}},{"id":"REQ-ISO-AP-1","clauseRef":"5.9","requirement":"The product shall take steps to reduce the risk that errors or crashes in one website running in one tab cause other, unrelated tabs to crash.","applicability":{},"assessment":null},{"id":"REQ-ISO-AP-2","clauseRef":"5.9","requirement":"The product shall take steps, on a best-effort basis, to save the state of running websites such that they can be restored later following an incident.\n\nEditor's note: Need conclusion wrt this being about page state such as scroll position, form data or storage or unspecific or more specific.","applicability":{},"assessment":null},{"id":"REQ-STORE-AP-1","clauseRef":"5.9","requirement":"The product shall retain data stored to disk in case of a crash and make it available upon browser restart.","applicability":{},"assessment":{"accId":"ACC-STORE-AP-1","reference":"The product shall retain data stored to disk in case of a crash and make it available upon browser restart.","objective":"Assess that in the case of a crash the data stored to disk is made available upon browser restart.","preparation":"- Prepare a method to induce crash\n    - Prepare tooling to inspect the data stored within the browser.\n    - Website that will store data","activities":"1. Visit website and verify it has set data.\n    2. Follow steps to induce crash\n    3. Restart browser\n    4. Verify data exists in browser.\n    5. Visit website and verify that the data is available to it.","verdict":"- **Pass**: Data set by the website during the first step is presented back to site during final step.\n    - **Fail**: The above is not fulfilled.","evidence":"Screenshot(s) or log output from tooling to demonstrate verdict.","guidance":""}}]},{"id":"5.10","clause":"5.10","title":"Impact Minimisation","overview":"Proposed ESR code: IM\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (i).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-IM-1","clauseRef":"5.10","requirement":"The web browser's technical documentation shall describe all network protocols implemented by the browser, or include references to such protocols. These protocols shall either be industry standards (preferably), or be described with similar technical detail to industry standards.","applicability":{},"assessment":null},{"id":"REQ-EXT-IM-1","clauseRef":"5.10","requirement":"If the product is running with elevated system privileges, extensions will be prevented from executing with those elevated privileges.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-IM-1","reference":"If the product is running with elevated system privileges, extensions will be prevented from executing with those elevated privileges.","objective":"Failure mode: an extension inherits the elevated OS privileges of an elevated product process (privilege inheritance).","preparation":"- Test extension.\n- Product launched with elevated privileges using the method provided on the operating system.\n- Tool for process inspection.","activities":"The following steps are to be carried out in order:\n\n1. Launch the product with elevated privilege.\n2. Install a test extension.\n3. Inspect the extension process and record its privilege.","verdict":"- **Pass**:\n  - The process running the extension does not have the elevated privileges of the main product process or processes.\n- **Fail**:\n  - The process running the extension carries the elevated privileges of the product process.","evidence":"Process inspection log.","guidance":""}},{"id":"REQ-EXT-IM-2","clauseRef":"5.10","requirement":"The product shall permit extensions to communicate with native applications only when declared in the extension manifest and the native application is configured according to the product requirements for doing so.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-IM-2","reference":"The product shall permit extensions to communicate with native applications only when declared in the extension manifest and the native application is configured according to the product requirements for doing so.","objective":"Failure mode: an extension communicates with undeclared, unconfigured, or misconfigured native applications (unauthorized native-app communication).","preparation":"- Test extension declaring a native application configured per vendor requirements, and a second application that is undeclared or unconfigured.\n- Tool for observing application communication in the OS, or control of the native application configured.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension.\n2. Connect to the declared and configured application.\n3. Connect to the undeclared application.\n4. Remove the application configuration, connect again from the extension.","verdict":"- **Pass**:\n  - Only the declared and configured application is reachable.\n  - Removing configuration breaks the connection.\n- **Fail**:\n  - Any undeclared, unconfigured, or misconfigured native application is reachable from the extension.","evidence":"Extension console logging.\nNative application logging.","guidance":""}},{"id":"REQ-EXT-IM-3","clauseRef":"5.10","requirement":"The product shall not permit an extension to initiate connections to services on the loopback interface (e.g., `localhost` or `127.0.0.1`) unless localhost access is declared in the extension manifest.\n\nEditor's note [OPEN]: Confirm that major browsers currently enforce this.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-IM-3","reference":"The product shall not permit an extension to initiate connections to services on the loopback interface (e.g., `localhost` or `127.0.0.1`) unless localhost access is declared in the extension manifest.","objective":"Failure mode: an extension without a localhost manifest declaration reaches a service on the loopback interface (undeclared loopback access).","preparation":"- Webserver bound to the loopback interface.\n- A hosts-file entry mapping a non-loopback hostname to a loopback address.\n- Loopback address variants to exercise: `localhost`, `127.0.0.1`, `::1`, `0.0.0.0`, a `*.localhost` subdomain, and the hosts-file hostname.\n- Test extension declaring localhost access.\n- Test extension not declaring localhost access.\n- Tool for observing local network traffic.","activities":"The following steps are to be carried out in order:\n\n1. Install the declaring extension and attempt connection to the webserver via each variant.\n2. Install the non-declaring extension and attempt connection via each variant.","verdict":"- **Pass**:\n  - The declaring extension connects via every variant.\n  - The non-declaring extension is blocked on every variant.\n- **Fail**: Any of the above are not fulfilled.","evidence":"Localhost network traffic log.","guidance":""}},{"id":"REQ-ISO-IM-1","clauseRef":"5.10","requirement":"The product's technical documentation shall describe all public network protocols implemented by the product, or include references to such protocols. These protocols shall be described in publicly available specifications, or be described with sufficient technical detail to permit an independent implementation.\n\nEditor's note: Discussion around this was not concluded. HAS did not like asking for technical docs. Sam raised asking for user docs instead. Andrew suggested that in some circumstances it's not needed at all, eg explicit cooperation between client and server. Daniel E had concerns about lowering the bar even in cooperation contexts.","applicability":{},"assessment":null},{"id":"REQ-PWR-IM-1","clauseRef":"5.10","requirement":"The product shall deny cross-origin iframes access to Powerful Web Platform Features by default.","applicability":{},"assessment":{"accId":"ACC-PWR-IM-1","reference":"The product shall deny cross-origin iframes access to Powerful Web Platform Features by default.","objective":"The product prevents cross-origin iframes from accessing Powerful Web Platform Features without explicit delegation from the top-level document.","preparation":"- The product installed from scratch, or reset to its default settings.\n- A top-level test web page hosted on Origin A.\n- An embedded cross-origin iframe hosted on Origin B inside the test page, configured without any explicit permission delegation.\n- A script in the cross-origin iframe attempting to request a Powerful Web Platform Feature.","activities":"The following steps are to be carried out in order:\n\n1. Load the top-level test web page.\n2. Trigger the script to request the Powerful Web Platform Feature from within the embedded cross-origin iframe.","verdict":"- **Pass**:\n    - Access to the feature is blocked for the cross-origin iframe automatically, without prompting the user.\n- **Fail**:\n    - The above is not fulfilled.","evidence":"Console logs and/or UI captures from the test web page showing access to the Powerful Web Platform Feature is being blocked.","guidance":""}}]},{"id":"5.11","clause":"5.11","title":"Minimisation of Attack Surfaces","overview":"Proposed ESR code: MAS\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (j).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-MAS-1","clauseRef":"5.11","requirement":"The web browser's technical documentation shall describe all web-exposed interfaces, or include references to such descriptions. These interfaces shall either be industry standards (preferably), or be described with similar technical detail to industry standards.","applicability":{},"assessment":null},{"id":"REQ-MAS-2","clauseRef":"5.11","requirement":"The web browser shall apply fuzz testing to web-exposed interfaces including HTML, CSS, JavaScript, WebAssembly, HTTP and TLS, as well as APIs, headers, options, etc exposed within those interfaces.","applicability":{},"assessment":null},{"id":"REQ-EXT-MAS-1","clauseRef":"5.11","requirement":"The product's extension APIs shall be documented, and the documentation shall specify for each API the purpose, inputs and outputs, permissions required, its security-related behaviour, and the platforms the API is available on.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-MAS-1","reference":"The product's extension APIs shall be documented, and the documentation shall specify for each API the purpose, inputs and outputs, permissions required, its security-related behaviour, and the platforms the API is available on.","objective":"All extension APIs supported by the product are documented with their purpose, inputs and outputs, permissions, security aspects, and platform availability.","preparation":"- Product extension API documentation.","activities":"- Review documentation of each supported API for the elements in the requirement","verdict":"- **Pass**:\n  - Each supported API is documented with the required elements.\n- **Fail**:\n  - Any of the above are not fulfilled.\n  - Undocumented APIs are reachable at runtime that are not on the documented surface.\n  - Documented API behavior diverges from the actual implementation.","evidence":"Log of documentation review.","guidance":""}},{"id":"REQ-EXT-MAS-2","clauseRef":"5.11","requirement":"The product shall support enterprise policy controls allowing administrators to disable the extension feature entirely, or specify an allow-list of extensions.","applicability":{"UC-CONS":"not-required","UC-INST":"required","UC-ETAB":"not-required"},"applicabilityText":"Enterprise browsers (UC-INST)\n\nPer clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-MAS-2","reference":"The product shall support enterprise policy controls allowing administrators to disable the extension feature entirely, or specify an allow-list of extensions.","objective":"The product supports using enterprise policy to disable extensions entirely, or restricting loaded extensions via an allow-list.","preparation":"- Applicability: Enterprise browsers (UC-INST).\n- Test environment that can apply the enterprise-policy support in the product per the supplied technical documentation.\n- Two test extensions.","activities":"The following steps are to be carried out in order:\n\n1. Apply a policy to disable all extensions.\n2. Attempt to install an extension.\n3. Remove the policy.\n4. Apply a policy containing an allow list of one of the two test extensions.\n5. Attempt to install both test extensions.\n6. Remove the policy.","verdict":"- **Pass**:\n  - Each policy has the specified effect.\n  - Removing each policy reverts to product default behavior.\n- **Fail**:\n  - Any of the above are not fulfilled.\n  - Policy is enforced for new installs but pre-installed extensions remain active.","evidence":"User interface capture.\nEnterprise policy logging if applicable.","guidance":""}},{"id":"REQ-EXT-MAS-3","clauseRef":"5.11","requirement":"The product shall enforce the scope of extension resources available to web content, as declared in the manifest.\n\nExample: Extensions may bundle assets in their packages, and browsers may allow them provide web pages with access to static assets, such as images, scripts and styles. Extensions declare these assets in their manifest, and browsers restrict access to only the declared assets.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-MAS-3","reference":"The product shall enforce the scope of extension resources available to web content, as declared in the manifest.","objective":"Failure mode: undeclared extension resources are reachable by web content (resource scope bypass).","preparation":"- Test extension declaring static assets as available to web content, and containing static assets which are not declared.\n- Test web page accessing the declared and undeclared resources in the extension.","activities":"The following steps are to be carried out in order:\n\n1. Install extension.\n2. Load test web page.","verdict":"- **Pass**:\n  - Declared resources are accessible by the test page as declared.\n  - Undeclared assets not accessible by the test page.\n- **Fail**:\n  - Undeclared resources are reachable by the test page.","evidence":"Test page source code.\nNetwork logging.\nExtension source code.","guidance":""}},{"id":"REQ-ISO-MAS-1","clauseRef":"5.11","requirement":"The product's technical documentation shall describe all web-exposed interfaces, or include references to such descriptions. These interfaces shall be described in publicly available specifications, or be described with sufficient technical detail to permit an independent implementation.","applicability":{},"assessment":null},{"id":"REQ-SOP-MAS-1","clauseRef":"5.11","requirement":"The product shall enforce restrictions from a source origin on how its resources may be used across origins, as defined in the user documentation.\n\nExample: Usage of cross-origin options such as `X-Frame-Options` or `Cross-Origin-Resource-Policy` allow source origins to specify usage constraints for products to receive and enforce.","applicability":{},"assessment":null},{"id":"REQ-MEM-MAS-1","clauseRef":"5.11","requirement":"The web browser shall use operating system functionality to restrict the capabilities and privileges of architectural components of the web browser.\n\nExample: Via sandboxed processes, system call filtering.","applicability":{},"assessment":{"accId":"ACC-MEM-MAS-1","reference":"The web browser shall use operating system functionality to restrict the capabilities and privileges of architectural components of the web browser.","objective":"The web browser takes steps to limit exposed operating system attack surface, which also serves to limit the consequences of successful exploitation, unless a documented functional requirement necessitates elevated privileges.","preparation":"- Documentation describing the operating system functionality used by the web browser to limit exposed operating system attack surface and limit the consequences of successful exploitation.\n- Documentation describing how those methods are applied to the architectural components of the web browser.\n- For architectural components to which those methods are not applied, documentation describing the rationale for this decision, and mitigations in place to reduce exploitation risk.\n- The web browser's source code.\n- Tools to inspect a running binary.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. For each method of operating system functionality listed in the web browser documentation, confirm via spot checks of the source code that the method is applied in accordance with the documentation.\n3. Run tools to inspect the running web browser.","verdict":"- **Pass**:\n    - The documentation describes operating system functionality that can limit exposed operating system attack surface, and limit the consequences of successful exploitation.\n    - The documentation maps those methods to the architectural components of the web browser.\n    - For each of the methods listed in the documentation as not being applied to an architectural component, the documentation convincingly describes the rationale for this decision.\n    - The mitigations applied to relevant architectural components convincingly reduce the risk of exploitation.\n    - For each method that results in changes readily inspectable in a running binary, tooling confirms the method is in use.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation review.\nLog of tooling output.","guidance":""}}]},{"id":"5.12","clause":"5.12","title":"Exploitation Mitigation Mechanisms","overview":"Proposed ESR code: EMM\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (k).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-EMM-1","clauseRef":"5.12","requirement":"The web browser shall separate certain web browser components from each other to reduce the scope of exploits.\n\nExamples: Sandboxing JavaScript/WebAssembly from the rest of the renderer process, containing the renderer and networking in separate processes","applicability":{},"assessment":null},{"id":"REQ-EMM-2","clauseRef":"5.12","requirement":"The web browser shall isolate different sites from each other, including from side-channel attacks.\n\nExample: Process isolation of sites","applicability":{},"assessment":null},{"id":"REQ-EMM-3","clauseRef":"5.12","requirement":"The web browser shall reduce the privileges of its various components with respect to the operating system to the level required to perform their tasks.\n\nExample: In the context of a browser with the separation of a renderer and browser process, denying direct access of the renderer process to various OS system calls","applicability":{},"assessment":null},{"id":"REQ-EXT-EMM-1","clauseRef":"5.12","requirement":"The product shall enforce a Content Security Policy for extension pages and scripts injected into web content.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-EMM-1","reference":"The product shall enforce a Content Security Policy for extension pages and scripts injected into web content.","objective":"Failure mode: scripts execute despite CSP, whether inline scripts on an extension page or undeclared scripts injected into web content.","preparation":"- Test extension with an extension page containing inline script and also a content script injected into a web page.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension\n2. Load the extension page\n3. Load the test web page","verdict":"- **Pass**:\n  - Product console log shows that the inline remote script and the content script injected into the web page are both blocked.\n- **Fail**:\n  - Either the inline script on the extension page or the injected content script executes.\n  - CSP is enforced for `<script>` but bypassable via event handlers, `eval`, dynamic imports, Worker scripts, or trusted-types violations.\n  - CSP is applied in report-only mode rather than enforcing.","evidence":"Console log showing CSP blocks.","guidance":""}},{"id":"REQ-EXT-EMM-2","clauseRef":"5.12","requirement":"The product shall validate an extension's manifest before installation and update, reject manifests that are malformed or contain disallowed content, and ignore unrecognised optional fields.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-EMM-2","reference":"The product shall validate an extension's manifest before installation and update, reject manifests that are malformed or contain disallowed content, and ignore unrecognised optional fields.","objective":"The product validates extension manifests before install and update, rejects manifests that are malformed or contain disallowed content, and ignores only unrecognised optional fields. \"Disallowed content\" means a value in a known field that violates the product's documented manifest schema (e.g., a permission string outside the product's permission set, a disallowed CSP directive, an out-of-form host-permission pattern).","preparation":"- Product documentation of the manifest schema, including the permission set, allowed CSP directives, and required vs optional fields.\n- A valid baseline manifest, and variants for: malformed (invalid JSON), disallowed content in a known field, an unrecognised optional field, an unrecognised required field.","activities":"The following steps are to be carried out in order:\n\n1. Attempt install with each variant manifest, recording each result.\n2. Install the valid baseline, then attempt update with each variant, recording each result.","verdict":"- **Pass**:\n  - Install and update fail for the malformed, disallowed-content, and unrecognised-required-field variants.\n  - Install and update succeed for the unrecognised-optional-field variant, and the unknown field grants no capability.\n  - The valid baseline installs and updates successfully.\n- **Fail**:\n  - Any of the above are not fulfilled.\n  - Disallowed content is silently normalised or substituted with a default that grants more than requested.\n  - Update validation is looser than install validation.\n  - Early parse failure short-circuits validation and hides subsequent errors.","evidence":"User interface capture.\nExtension logs.","guidance":""}},{"id":"REQ-ISO-EMM-1","clauseRef":"5.12","requirement":"The product shall separate certain product components from each other to reduce the scope of exploits, using process isolation or similar industry standard mitigations.","applicability":{},"assessment":null},{"id":"REQ-ISO-EMM-2","clauseRef":"5.12","requirement":"The product shall isolate different sites from each other, including from side-channel attacks.","applicability":{},"assessment":null},{"id":"REQ-ISO-EMM-3","clauseRef":"5.12","requirement":"The product shall reduce the privileges of its various components with respect to the operating system to the level required to perform their tasks.","applicability":{},"assessment":null},{"id":"REQ-MEM-EMM-1","clauseRef":"5.12","requirement":"The web browser shall include runtime assertions as to the correctness of program state, which fail safely when violated.\n\nExample: Via the use of ASSERT() or CHECK() statements that result in an unexploitable crash.","applicability":{},"assessment":{"accId":"ACC-MEM-EMM-1","reference":"The web browser shall include runtime assertions as to the correctness of program state, which fail safely when violated.","objective":"The web browser contains runtime checks which help prevent the web browser from entering an unexpected state, which can lead to exploitable vulnerabilities.","preparation":"- Documentation describing the techniques developers can use to ensure that runtime invariants hold and fail in an unexploitable fashion.\n- The web browser's source code.","activities":"The following steps are to be carried out in order:\n\n1. Review the source code that implements the techniques developers can use to ensure that runtime invariants hold and fail in an unexploitable fashion.\n2. Review the usage of the techniques within the source code.","verdict":"- **Pass**:\n    - The techniques developers can use to ensure that runtime invariants hold and fail in an unexploitable fashion.\n    - The techniques are widely used within the source code.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of source code review.","guidance":""}},{"id":"REQ-MEM-EMM-2","clauseRef":"5.12","requirement":"The web browser shall use compiler features designed to reduce the risk of exploitation.\n\nExample: stack canaries, source code fortification, variable initialisation.","applicability":{},"assessment":{"accId":"ACC-MEM-EMM-2","reference":"The web browser shall use compiler features designed to reduce the risk of exploitation.","objective":"The web browser uses hardening features provided by the compiler.","preparation":"- Documentation describing the security relevant compiler flags and features that are enabled in the product's release configuration.\n- The web browser's source code and build configuration.\n- Tools to inspect compiled binaries.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. For each of the security relevant compiler flags and features listed in the web browser documentation, confirm via inspection of the web browser source code and build configuration that it is indeed being used in the build of the release configuration.\n3. Run tooling against the web browser's compiled binaries.","verdict":"- **Pass**:\n    - The compiler flags and features listed as being used in the web browser documentation are indeed being used in the build of the release configuration.\n    - For each security relevant compiler flag, the enablement of which results are readily inspectable in the resulting compiled binary, tooling output confirms the feature is in a state that matches the web browser documentation.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation review.\nLog of source code and build configuration review.\nLog of tooling output.","guidance":""}},{"id":"REQ-MEM-EMM-3","clauseRef":"5.12","requirement":"The web browser shall use mitigation technologies provided by the operating systems and/or hardware on which the web browser is designed to run.\n\nExample: hardware-assisted memory tagging, Address Space Layout Randomization.","applicability":{},"assessment":{"accId":"ACC-MEM-EMM-3","reference":"The web browser shall use mitigation technologies provided by the operating systems and/or hardware on which the web browser is designed to run.","objective":"The web browser uses hardening features provided by the operating system and/or hardware.","preparation":"- Documentation describing the mitigation technologies provided by the operating system and/or hardware on which the web browser is designed to run, which are used by the web browser.\n- Documentation describing the rationale for not using any mitigation technologies provided by the operating system and/or hardware on which the web browser is designed to run.\n- The web browser's source code and build configuration.","activities":"The following steps are to be carried out in order:\n\n1. Review the documentation.\n2. For each of the mitigation technologies listed in the web browser documentation, confirm via inspection of the web browser source code and build configuration that it is indeed being used in the release configuration.","verdict":"- **Pass**:\n    - The mitigation technologies listed in the web browser documentation are indeed being used by the release configuration of the web browser.\n    - For each of the mitigation technologies listed in the documentation as not being used, the documentation convincingly describes the rationale for this decision.\n- **Fail**:\n    - Any of the above are not fulfilled.","evidence":"Log of documentation review.\nLog of source code and build configuration review.","guidance":""}}]},{"id":"5.13","clause":"5.13","title":"Logging and Monitoring","overview":"Proposed ESR code: LOG\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (l).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-TLS-LOG-1","clauseRef":"5.13","requirement":"The product shall present a user interface giving visibility into the security properties of the connection, including the origin.","applicability":{},"assessment":{"accId":"ACC-TLS-LOG-1","reference":"The product shall present a user interface giving visibility into the security properties of the connection, including the origin.","objective":"The product presents a user interface giving visibility into the security properties of the connection, including the origin.","preparation":"- Identify multiple relevant websites with various levels of the security of their connections, at different origins.\n- Locate the relevant user interface based on the technical documentation of the product.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to each of the various websites identified.\n2. Open the security UI and observe the information displayed.","verdict":"- **Pass**: For each website, the UI includes the URL and any other relevant security properties of the connection.\n- **Fail**: Any of the above are not fulfilled.","evidence":"Screenshots of security UI for each website","guidance":""}},{"id":"REQ-EXT-LOG-1","clauseRef":"5.13","requirement":"The product shall provide the user the ability to identify which user-installed extensions are currently running, and the permissions in effect for each.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-LOG-1","reference":"The product shall provide the user the ability to identify which user-installed extensions are currently running, and the permissions in effect for each.","objective":"The product provides a way to identify which user-installed extensions are currently running, and the permissions in effect for each.","preparation":"- User-installed test extension A, declaring two or more distinct permissions.\n- User-installed test extension B, with a background script or service worker as its only runtime.\n- Product documentation locating the running-extensions interface.","activities":"The following steps are to be carried out in order:\n\n1. Install both test extensions.\n2. Open the running-extensions interface and record which extensions and permissions are shown.\n3. Install a third user extension while the interface is open and record whether it appears without a restart.","verdict":"- **Pass**:\n  - Both test extensions are listed, including the background-only one.\n  - The permissions shown for each match the permissions in effect.\n  - The third extension appears without a restart.\n- **Fail**: Any of the above are not fulfilled.","evidence":"User interface captures.","guidance":""}},{"id":"REQ-STORE-LOG-1","clauseRef":"5.13","requirement":"The product shall provide an interface for viewing information about stored data at a granularity of site or narrower (e.g. origin).","applicability":{},"assessment":{"accId":"ACC-STORE-LOG-1","reference":"The product shall provide an interface for viewing information about stored data at a granularity of site or narrower (e.g. origin).","objective":"Assess that the product provides an interface for viewing information about stored data at a granularity of site or narrower.","preparation":"- Prepare tooling to inspect the data stored within the browser.\n    - User documentation describing process for deleting data.\n    - Website on site A that will store data, including:\n      - cookie data\n      - LocalStorage\n      - IndexedDB storage\n    - Website on site B that will store data, including:\n      - cookie data\n      - LocalStorage\n      - IndexedDB storage","activities":"1. Visit website on site A, and verify it has set data.\n    2. Visit website on site B, and verify it has set data.\n    3. Follow user documentation for deleting data against site A.\n    4. Verify whether data for site A has been removed.\n    5. Verify whether data for site B has been removed.","verdict":"- **Pass**:\n        - Data is set successfully during website vists.\n        - User documentation provides clear steps for removing data at a site level.\n        - Data is successfully removed from site A.\n        - Data is not removed from site B.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot or log output from tooling at each step to show data.\nUser documentation providing instructions for data removal.","guidance":""}},{"id":"REQ-PWR-LOG-1","clauseRef":"5.13","requirement":"The product shall provide a user interface listing the Powerful Web Platform Features granted or denied to the web page being displayed.","applicability":{},"assessment":{"accId":"ACC-PWR-LOG-1","reference":"The product shall provide a user interface listing the Powerful Web Platform Features granted or denied to the web page being displayed.","objective":"The product provides a user interface allowing the user to view the current permission status of Powerful Web Platform Features for the active web page.","preparation":"- The product installed from scratch, or reset to its default settings.\n    - A test web page that uses several Powerful Web Platform Features.","activities":"The following steps are to be carried out in order:\n\n1. Navigate to the test web page.\n2. Trigger two feature requests: grant access to the first, and deny access to the second.\n3. Open the product's site-specific security/permissions UI.","verdict":"- **Pass**:\n    - The UI accurately lists the specific Powerful Web Platform Features and explicitly reflects their current states as \"granted/allowed\" and \"denied/blocked\" for that page.\n    - Applying the setting automatically blocks the test web page's access to the Powerful Web Platform Feature without presenting a permission prompt to the user.\n- **Fail**:\n    - The UI is missing, or it does not accurately reflect the active permission states.","evidence":"UI screenshots of the site information/permission panel showing the correct status.","guidance":""}}]},{"id":"5.14","clause":"5.14","title":"Data Removal and Transparency","overview":"Proposed ESR code: DRT\n\nThis clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 1 (2) (m).","addressedBy":[],"otherRequirements":[],"requirements":[{"id":"REQ-TLS-DRT-1","clauseRef":"5.14","requirement":"The product shall make available functionality to reset TLS-related functionality to the initial safe settings, including selection of algorithms and protocol versions, root certificates, and any other relevant properties.","applicability":{},"applicabilityText":"Web browsers which allow changing TLS-related settings.","assessment":{"accId":"ACC-TLS-DRT-1","reference":"The product shall make available functionality to reset TLS-related functionality to the initial safe settings, including selection of algorithms and protocol versions, root certificates, and any other relevant properties.","objective":"The product provides functionality that resets TLS-related settings to the initial safe configuration.","preparation":"- Install the product from scratch, or reset it to its default settings.\n- Capture the initial TLS-related state: enabled algorithms and protocol versions, trusted root certificates, and any other TLS-related settings.\n- Locate the reset functionality in the product UI or documentation.","activities":"The following steps are to be carried out in order:\n\n1. Modify TLS-related state from its initial values, such as disabling a protocol version, adding a custom trusted root, or altering a TLS-related setting.\n2. Exercise the reset functionality.\n3. Capture the post-reset TLS-related state.\n4. Compare the post-reset state against the initial snapshot.","verdict":"- **Pass**:\n  - The reset functionality is available and exercisable.\n  - The post-reset state matches the initial state across all modified TLS-related properties.\n- **Fail**: Either of the above is not fulfilled.","evidence":"TLS state snapshots before modification, after modification, and after reset.","guidance":""}},{"id":"REQ-EXT-DRT-1","clauseRef":"5.14","requirement":"The product shall enable the removal of individual extensions, which shall delete all data associated with the extension, and revoke all permissions granted to it.","applicability":{},"applicabilityText":"Per clause 5.1: “The extension-related requirements apply to products that offer the installation of third party extensions. Products not offering third party extension support are out of scope for those requirements.”","assessment":{"accId":"ACC-EXT-DRT-1","reference":"The product shall enable the removal of individual extensions, which shall delete all data associated with the extension, and revoke all permissions granted to it.","objective":"Failure mode: data or granted permissions remain after extension removal (residual state).","preparation":"- Test extension installed with several permissions requested, and which writes to its storage area.\n- Tool for viewing product extension storage.","activities":"The following steps are to be carried out in order:\n\n1. Install the test extension, granting all permissions requested.\n2. Inspect the extension storage area, verifying the extension data was written.\n3. Remove the extension from the product.\n4. Inspect each storage area again, and user interface for permissions management.","verdict":"- **Pass**:\n  - After extension removal there is no data in the storage area or granted permissions.\n- **Fail**:\n  - After removal, extension data remains in the storage area, or permissions granted to the extension remain in effect.\n  - Extension data persists in profile or cloud sync after local removal.\n  - Tab-local state and in-memory caches are retained until product restart.\n  - Some storage areas (newer or platform-specific APIs) are missed by the inspection.","evidence":"Storage and permission inspection before and after extension removal.","guidance":""}},{"id":"REQ-STORE-DRT-1","clauseRef":"5.14","requirement":"The product shall ensure when storage data is deleted, it uses appropriate APIs that ensure the data is deleted from the underlying storage device.","applicability":{},"assessment":{"accId":"ACC-STORE-DRT-1","reference":"The product shall ensure when storage data is deleted, it uses appropriate APIs that ensure the data is deleted from the underlying storage device.","objective":"Assess that in cases of storage data deletion, the data is effectively deleted.","preparation":"- Access to product source code.\n    - Access to integration API documentation.\n    - Any required test tooling for verification of memory.","activities":"- Identify internal APIs that provide for the deletion of storage data.\n    - Identify all implementations of the APIs.\n    - Identify underlying system APIs used for data management, and their accompanying documentation.","verdict":"- **Pass**:\n        - For each storage deletion API implementation, each has either\n            - System vendor documentation for the system API, providing guarantee of deletion, or\n            - Test that upon calling API, underlying data is deleted from memory.\n    - **Fail**: Any of APIs where one of the criteria are not fulfilled.","evidence":"List of internal APIs implementations providing storage deletion.\nCorresponding list of underlying system APIs, and documentation their references.\nScreenshot(s) or log output from test tooling for each API in the case of manual test verification.","guidance":""}},{"id":"REQ-STORE-DRT-2","clauseRef":"5.14","requirement":"The product shall provide reset functionality that removes all stored data across all sites and browser profiles.","applicability":{},"assessment":{"accId":"ACC-STORE-DRT-2","reference":"The product shall provide reset functionality that removes all stored data across all sites and browser profiles.","objective":"Assess that the reset functionality removes all stored data across all sites and browser profiles.","preparation":"- Prepare tooling to inspect browser profiles and data stored within browser.\n    - Website that will store instances of all data supported by the browser.\n    - Browser in factory default state.\n    - User documentation for performing browser reset.\n    - List of browser profile capabilities.","activities":"1. Verify with tooling only default browser profile exists, and no data is stored.\n    2. Create an instance of each supported browser profile.\n    3. Verify with tooling that each profile exists, and no data is stored.\n    4. With each profile, visit the website to set data.\n    5. Verify with tooling that each profile still exists, and has data stored.\n    6. Follow user documentation for performing reset.\n    7. Verify with tooling only default browser profile exists, and no data is stored.","verdict":"- **Pass**: At each verification step, the expected profiles and data are present.\n    - **Fail**: The above is not fulfilled.","evidence":"Screenshot(s) or log output from tooling at each step to show data.\nUser documentation for performing reset.","guidance":""}},{"id":"REQ-STORE-DRT-3","clauseRef":"5.14","requirement":"The product shall have a user interface for deleting storage at a granularity of site or narrower (e.g. origin).","applicability":{},"assessment":{"accId":"ACC-STORE-DRT-3","reference":"The product shall have a user interface for deleting storage at a granularity of site or narrower (e.g. origin).","objective":"Assess that the product provides an interface for users to delete storage at a granularity of site or narrower.","preparation":"- Prepare tooling to inspect the data stored within the browser.\n    - User documentation describing process for deleting data.\n    - Website on site A that will store data, including\n      - cookie data,\n      - LocalStorage, and\n      - IndexedDB storage.\n    - Website on site B that will store data, including\n      - cookie data,\n      - LocalStorage, and\n      - IndexedDB storage.","activities":"1. Visit website on site A, and verify it has set data.\n    2. Visit website on site B, and verify it has set data.\n    3. Follow user documentation for deleting data against site A.\n    4. Verify whether data for site A has been removed.\n    5. Verify whether data for site B has been removed.","verdict":"- **Pass**:\n        - Data is set successfully during website vists.\n        - User documentation provides clear steps for removing data at a site level.\n        - Data is successfully removed from site A.\n        - Data is not removed from site B.\n    - **Fail**: Any of the above are not fulfilled.","evidence":"Screenshot(s) or log output from tooling at to demonstrate each verdict.\nUser documentation providing instructions for data removal.","guidance":""}},{"id":"REQ-PWR-DRT-1","clauseRef":"5.14","requirement":"The product shall provide a user interface allowing revocation of previously granted permissions for Powerful Web Platform Features.","applicability":{},"assessment":{"accId":"ACC-PWR-DRT-1","reference":"The product shall provide a user interface allowing revocation of previously granted permissions for Powerful Web Platform Features.","objective":"Permission to use Powerful Web Platform Features granted to a web page can be easily revoked by the user via a provided interface.","preparation":"- The product installed from scratch, or reset to its default settings.\n    - A test web page that uses a Powerful Web Platform Feature.","activities":"The following steps are to be carried out in order:\n\n1. Load the test page, trigger the request, and explicitly grant the permission.\n2. Verify the web page can successfully access the feature.\n3. Open the product's user interface (either site-specific controls or global settings) and revoke the permission.\n4. Reload the test page and attempt to use the feature again.","verdict":"- **Pass**:\n    - The product provides a UI to revoke the permission.\n    - The revocation UI indicates the permission is removed, and the web page loses access to the feature.\n- **Fail**:\n    - The revocation UI is missing.\n    - The revocation UI indicates the permission is removed, but the web page retains access.","evidence":"UI screenshots of the revocation process.\nConsole logs and/or UI captures from the test web page showing no access to the Powerful Web Platform Features after revocation.","guidance":""}}]},{"id":"5.15","clause":"5.15","title":"Vulnerability Handling","overview":"This clause addresses the requirements in the CRA [i.1\\] Annex 1 Part 2.\n\nThe requirements specified in CEN/CLC JT013090:2026 (CEN/CLC prEN 40000-1-3) [2\\] shall be fulfilled for the product.","addressedBy":[],"otherRequirements":[],"requirements":[]}],"annexK":{"general":"ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will have to be deleted or replaced by relevant references and notes before publication. Once the text of this Annex will be agreed, the definitions included in the notes will be moved to Clause 3 of the present document.\n\n> NOTE: the text of this annex is currently being edited, not final.","requirements":[{"id":"K.1.1","clauseRef":"K.1.1","family":"Annex K — Cryptography","requirement":"The product shall, by default, use State-of-the-Art cryptography algorithms listed in (CRY-SOTA), to be used for the supported security mechanism of the product where applicable.\n\n> NOTE 1: The use of _security mechanism e.g. authentication, access control, secure communication, secure storage and secure update are described in the main text of this standard._\n\n> NOTE 2: Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the [ACM][^1] document and are suitable for the implementation of supported security mechanisms of the product.\n\n> NOTE 3: Supporting evidence options that an algorithm, which is not included in CRY-SOTA, is applicable and suitable for the respective use case, are listed in the related assessment criteria ( K.1.2.1) clause.","applicability":{},"applicabilityText":"Annex K is normative for the product's cryptography. Clause 5.6 states: “In this clause, reference can be made to the Annex K (normative), specifying State Of The Art Cryptography”. The requirement itself is conditioned “where applicable” on the product's supported security mechanisms.","assessment":{"objective":"The purpose of this assessment case is (the conceptual assessment) whether the implemented algorithms are identified as CRY-SOTA.","preparation":"- Preconditions for the test: If applicable, the product is in the default- configuration. Otherwise, the product is in the delivery state, where it is available on the market in accordance with CRA Annex I part 1(2) (b).","activities":"- For every security mechanism the list of used algorithms, which are reachable over an external interface and identified as CRY- SOTA shall be documented.","verdict":"- The verdict PASS shall be assigned if evidence has been provided.\n\n- The verdict FAIL shall be assigned otherwise\n\nIf the verdict in K.1.2.1 has been assigned FAIL, the following assessment has to be performed additionally:","evidence":"description of the performed test\nall test records of the performed test","guidance":"The draft adds a conditional follow-up assessment (its heading number K.1.2.2 is duplicated in the draft), quoted verbatim:\n\n#### K.1.2.2 Additional conditional assessment:\n\n##### K1.2.2.1 Assessment objective\n\nIf for a certain security mechanism and use case no CRY-SOTA algorithm is applicable, evidence shall be provided in the documentation that a suitable algorithm has been implemented for this evidence instead.\n\n##### K.1.2.2.2 Assessment preparation:\n\nPreconditions for the test: If applicable, the product is in the default configuration state. Otherwise, the product is in the delivery state, where it is available on the market in accordance with CRA Annex I part 1(2) (b).\n\n##### K.1.2.2.3 Assessment activities:\n\nFor every security mechanism and for every used algorithm, which is reachable over an interface of the product and identified as not included in CRY- SOTA, the documentation shall provide evidence\n\n- that this algorithm is applicable and suitable for the respective use case\n\n#### K.1.2.4 Supporting Evidence:\n\n1. Identification of the certain algorithm by reference in further  publicly available  applicable algorithm catalogues as  national cryptographic catalogues[^2] or vertical use case specific cryptographic algorithm catalogues[^3]\n\n2. No entry of known exploitable vulnerabilities  provided in  ENISA  \"European Vulnerability Database.[^4]\n\n3. Description of the performed test\n\n4. all test records of the performed test\n\n#### K.1.2.5 Assignment of verdict:\n\n- The verdict PASS shall be assigned if respective evidence has been provided,\n- The verdict FAIL shall be assigned otherwise.\n\n> NOTE 3: Functional correctness and completeness assessment criteria of the documentation are to be specified in accordance with the capabilities set in the specific vertical Standards.\n\n[^1]: defined in [ACM]\n[^2]: e.g. BSI – BSI TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths , Vers. 2025-01, January 31, 2025\n[^3]: e.g. EPC342-08 /Version 15.0 /Guidelines on cryptographic algorithms usage and key management - PPSSG / 7 March 2025\n[^4]: European Vulnerability Database established pursuantto Article 12(2) of Directive (EU) 2022/2555, https://euvd.enisa.europa.eu/ENISA"}},{"id":"K.2","clauseRef":"K.2","family":"Annex K — Cryptography","requirement":"Where applicable the product shall by default be prepared to update cryptographic algorithm used for the supported security mechanism of the product to maintain when there are indications that the used cryptographic algorithm will not stay SOTA anymore within the intended lifetime of the product.\n\n> NOTE 4: To maintain SOTA for cryptographic algorithm within the intended lifetime of the product concepts to consider are crypto agility additional to the capability of updating cryptographic algorithms on the product in accordance to Secure Update and Secure Communication mechanism.\n\n> NOTE 5: Formal verification can use mathematical proofs and /or rigorous methods to prove an algorithm's correctness, ensuring it meets its formal specification for all valid inputs, unlike testing which only samples cases. This process involves creating formal models, using techniques like [theorem proving](theorem proving) or [model checking](model checking), and is crucial for critical systems like [cryptography](cryptography) finding hard-to-spot bugs and guaranteeing security/reliability**_._**\n\n> NOTE 6: The [ACM] listing has two classes of SOTA algorithms; **Legacy mechanisms** with an expiry date as defined in ACM, and **Recommended mechanisms** with no set expiry date.\n\n> NOTE 7: For products or components of products that cannot have their cryptographic algorithms updated for example if the implementation or part uses a hardware-based root of trust, it is important that the intended lifetime of the equipment does not exceed the recommended usage lifetime of the cryptographic algorithms used by the product. Thereby the implementation of an algorithm can include the specific implementation of their parameters\n\n> NOTE 8: If a component storing the algorithm or corresponding parameters of a main product is replaced by a new component, the product is considered as a new product according to the New Legislative Framework Blue Guide, if the replacement provides a substantial modification to the main product","applicability":{},"applicabilityText":"Annex K is normative for the product's cryptography. Clause 5.6 states: “In this clause, reference can be made to the Annex K (normative), specifying State Of The Art Cryptography”. The requirement itself is conditioned “where applicable” on the product's supported security mechanisms.","assessment":{"objective":"The purpose of this assessment case is (the conceptual assessment) whether the product is prepared to update cryptographic algorithms for the supported security mechanism.","preparation":"- Preconditions for the test: If applicable, the product is in the default- configuration. Otherwise, the product is in the delivery state, where it is available on the market in accordance with CRA Annex I part 1(2) (b).","activities":"- For every used SOTA algorithm, which is reachable over an interface, the life span of the algorithm is documented, as well its property, if the algorithm is considered as legacy or recommended algorithm.[^5]\n- If the life span of the product exceeds the life span of a legacy algorithm, the algorithm is marked as updatable by a recommended algorithm in the documentation.\n- If an algorithm is identified as SOTA recommended, no further action is required.","verdict":"- The verdict PASS shall be assigned if respective evidence has been provided,\n- The verdict FAIL shall be assigned otherwise.\n<br />\n\n[^5]: defined in [ACM]","evidence":"Description /documentation of the performed test.\nAll test records of the performed test.","guidance":""}}]},"rdps":{"applicability":"","families":[],"requirements":[]},"threats":[{"id":"T-01","title":"Cross-origin separation failure","description":"An attacker origin bypasses origin restrictions or structured cross-origin controls. Impact / violated invariant: Direct confidentiality/integrity loss; violates origin-based isolation. (Applicable use cases: GP, EN, EB.)"},{"id":"T-02","title":"Origin-compromising active content and persistence abuse","description":"Malicious or injected script executes with origin authority, optionally persisting. Impact / violated invariant: Same-origin authority abuse. (Applicable use cases: GP, EN, EB.)"},{"id":"T-03","title":"Capability escalation through permissioned surfaces","description":"A malicious origin acquires or abuses permissioned capability surfaces. Impact / violated invariant: Non-ambient access assumptions are weakened. (Applicable use cases: GP, EN, EB.)"},{"id":"T-04","title":"XS-Leaks / cross-site inference","description":"The attacker does not directly read cross-origin content, but infers state through observable side effects of cross-site interaction. Impact / violated invariant: Violates the invariant that cross-site behavior should not become an unintended oracle for sensitive state. (Applicable use cases: GP, EN.)"},{"id":"I-01","title":"Renderer / engine compromise","description":"Malicious content exploits engine or renderer bugs. Impact / violated invariant: Confinement fails. (Applicable use cases: GP, EN, EB.)"},{"id":"I-02","title":"Timing / grouping implementation choices preserve or amplify inference surface","description":"Timer precision, browsing-context grouping, or result handling preserve signals attackers can measure. Impact / violated invariant: XS-Leaks surface grows despite correct direct-read enforcement. (Applicable use cases: GP, EN.)"},{"id":"I-03","title":"Storage, cookie, or credential handling defects","description":"Incorrect credential or state scoping affects when cross-site requests carry state. Impact / violated invariant: Cross-site oracle surface expands. (Applicable use cases: GP, EN.)"},{"id":"E-01","title":"Passive or active network attack","description":"Attacker observes or tampers with traffic. Impact / violated invariant: Transport guarantees fail. (Applicable use cases: EB.)"},{"id":"E-02","title":"Trusted-UI spoofing and consent deception","description":"Malicious site imitates browser UI or abuses confusing flows. Impact / violated invariant: Phishing and unsafe consent. (Applicable use cases: GP, EN.)"},{"id":"E-03","title":"Cross-site inference attacker","description":"A malicious origin deliberately probes another site through permitted cross-site interactions and observes side effects. Impact / violated invariant: Sensitive cross-site state becomes inferable without direct reads. (Applicable use cases: GP, EN.)"},{"id":"D-01","title":"PKI / transport trust failure","description":"External trust failure weakens secure transport assumptions. Impact / violated invariant: Wrong-endpoint trust or downgrade exposure. (Applicable use cases: GP, EN, EB.)"},{"id":"D-02","title":"Server-side state-dependent behavior becomes oracle","description":"Server emits redirects, error codes, or load behavior that differ by state. Impact / violated invariant: Browser-enforced read restrictions do not stop inference. (Applicable use cases: EN.)"},{"id":"D-03","title":"OS / kernel compromise below browser controls","description":"Local privileged compromise defeats browser confinement. Impact / violated invariant: Browser-enforced boundaries collapse. (Applicable use cases: GP, EN, EB.)"}],"draftGaps":["The draft carries 29 <mark>-flagged editor's notes/open issues (draft version v0.1.1, 2026-04-04), including two TODOs about requirements that may be implied by Annex K (REQ-TLS-SBD-1, REQ-TLS-CON-1) and unresolved discussions on REQ-ISO-IM-1 and REQ-SOP-AAC-2.","No per-use-case applicability matrix exists yet: clause 5.1 carries an editor's note that a matrix mapping use cases to requirements \"should be inserted\". Only 3 requirements carry their own \"Applicability:\" prose naming use-case ids, from which a required/not-required map was derived; every other requirement is carried with an empty applicability map (treated as applicable to all use cases).","24 of 83 clause-5 requirements have NO assessment block in clause 6 of this interim draft: REQ-KEV-1, REQ-KEV-2, REQ-STORE-ACC-3, REQ-SOP-AAC-1, REQ-SOP-AAC-2, REQ-TLS-CON-6, REQ-SOP-CON-1, REQ-SOP-CON-2, REQ-AP-1, REQ-AP-2, REQ-ISO-AP-1, REQ-ISO-AP-2, REQ-IM-1, REQ-ISO-IM-1, REQ-MAS-1, REQ-MAS-2, REQ-ISO-MAS-1, REQ-SOP-MAS-1, REQ-EMM-1, REQ-EMM-2, REQ-EMM-3, REQ-ISO-EMM-1, REQ-ISO-EMM-2, REQ-ISO-EMM-3. Their packs entries carry assessment: null.","Clause 6's block [ACC-STORE-AAC-1] targets “REQ-STORE-AAC-1”, an id clause 5 never defines; the pack attaches it to REQ-STORE-ACC-1, whose text its Assessment Reference restates. Related draft inconsistency: clause 5.5 announces ESR code “AAC” but the STORE requirements in it use “ACC” (REQ-STORE-ACC-1..3).","REQ-TLS-CON-6 exists but no REQ-TLS-CON-5 is defined — an id-sequence gap in the draft.","Clauses 5.9–5.12 contain near-duplicate requirement pairs (REQ-AP-1/2 vs REQ-ISO-AP-1/2; REQ-IM-1 vs REQ-ISO-IM-1; REQ-MAS-1 vs REQ-ISO-MAS-1; REQ-EMM-1/2/3 vs REQ-ISO-EMM-1/2/3) — apparently parallel drafts of the same provisions not yet merged. Both variants are carried verbatim.","Clause 5.15 (Vulnerability Handling) defines no REQ ids: it is a single normative sentence delegating to CEN/CLC JT013090:2026 (prEN 40000-1-3), and clause 6.15 likewise delegates its assessment. The pack carries no answerable entry for it; CRA Annex I Part 2 remains assessed through the horizontal pack.","Clause 6.3 is titled “Secure by design” while the corresponding clause 5.3 is “Secure by default configuration” — a draft heading mismatch.","Annex K is marked “currently being edited, not final” and contains duplicated heading numbers (two K.1.2.2 / K.1.2.4 / K.1.2.5 blocks); the Annex K entries' ids (K.1.1, K.2) are the draft's clause numbers, its only identifiers for them.","The Executive summary and Introduction clauses are template placeholders; Annex C, Annex <D...J> and Annex G are empty skeletons.","REQ-AP-1: use-case applicability derived from its own “Applicability:” prose (UC-CONS and UC-INST); unnamed use cases marked not-required.","REQ-AP-2: use-case applicability derived from its own “Applicability:” prose (UC-CONS and UC-INST); unnamed use cases marked not-required.","REQ-EXT-MAS-2: use-case applicability derived from its own “Applicability:” prose (Enterprise browsers (UC-INST)); unnamed use cases marked not-required.","clause 6 block [ACC-STORE-AAC-1] targets “REQ-STORE-AAC-1”, an id clause 5 never defines; attached to REQ-STORE-ACC-1, whose text its Assessment Reference restates."]}