|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
この動きは、ブラウザを介して高主権攻撃を停止し、すべてのプラットフォームでユーザーセキュリティを強化することを目的としています。

Google Chrome is set to get a little safer, especially on Windows, as it is adding a new security feature to Chrome that will automatically de-elevate the browser when it is launched with administrator privileges.
Google Chromeは、特にWindowsで少し安全になるように設定されています。これは、Chromeに新しいセキュリティ機能を追加して、管理者の特権で起動するとブラウザを自動的に除去するように設定されています。
This move is aimed at stopping high-privilege attacks through the browser and strengthening user security across all platforms.
この動きは、ブラウザを介して高主権攻撃を停止し、すべてのプラットフォームでユーザーセキュリティを強化することを目的としています。
The change, recently submitted via a Chromium code commit, builds on a similar mechanism introduced in Microsoft Edge back in 2019.
Chromiumコードコミットを介して最近提出されたこの変更は、2019年にMicrosoft Edgeで導入された同様のメカニズムに基づいています。
Spotted in the wild on Social Media
ソーシャルメディアで野生で発見されました
As spotted by Leo (@peva64) on X, the update is designed to improve system security by preventing Chrome from running in elevated mode unnecessarily. In other words, you will no longer be able to run Chrome as an “admin” user on Windows machines, unless absolutely necessary.
XでLEO(@PEVA64)が発見したように、この更新は、Chromeが不必要に高架モードで実行されないようにすることにより、システムセキュリティを改善するように設計されています。言い換えれば、絶対に必要でない限り、Windowsマシン上の「管理者」ユーザーとしてChromeを実行することはできなくなります。
Further, Chrome will now attempt to relaunch itself with standard user permissions when started with admin rights. If the first relaunch attempt fails, Chrome will fall back to the current behavior —running with elevated privileges — but only after ensuring it doesn’t get stuck in a relaunch loop.
さらに、Chromeは、管理者の権利から開始されたときに標準のユーザー許可で自らを再起動しようとします。最初の再起動の試みが失敗した場合、Chromeは現在の動作に戻ります - 特権の上昇で実行されます - しかし、それが再起動ループで立ち往生しないようにした後にのみ。
“Automatically de-elevate users launching chrome elevated. This CL is based on changes we’ve had in Edge, circa 2019, which attempts to automatically de-elevate the browser when it’s run with the elevated part of a split / linked token,” Stefan Smolen working with the Microsoft Edge team and one of the key contributors to this update, wrote in a Chromium commit.
「Chromeの高さを起動するユーザーが自動的に解放されます。このCLは、2019年頃にEdgeの変更に基づいています。これは、Stepsoft Edgeチームとこの更新の主要な貢献者の1つであるStefan Smolenが、スプリット /リンクされたトークンの高い部分で実行されたときにブラウザを自動的に除去しようとします。
“This automatically attempts a relaunch once, and then if it still fails it falls back to the current behaviour (which tries to launch admin).”
「これにより、自動的にリニューアルが一度試行され、それでも失敗した場合は、現在の動作に戻ります(管理者を起動しようとします)。」
Microsoft has also introduced a command-line switch, “-do-not-de-elevate,” to stop Chrome from de-elevating after an automatic relaunch. This helps prevent potential infinite relaunch loops when the browser fails to start with standard privileges.
Microsoftはまた、自動リニューアル後にChromeが脱却するのを防ぐために、コマンドラインスイッチ「-do-not-de-Elevate」を導入しました。これは、ブラウザが標準的な特権から開始できない場合、潜在的な無限のリニューアルループを防ぐのに役立ちます。
“Do not de-elevate the browser on launch. Used after de-elevating to prevent infinite loops,” reads a comment in the source code.
「起動時にブラウザを除外しないでください。無限のループを防ぐために脱線した後に使用されます」とソースコードのコメントを読みます。
However, this de-elevation won’t apply to Chrome processes launched with elevated rights in automation scenarios, ensuring compatibility with testing tools and scripts.
ただし、この解除は、自動化シナリオで権利が高まって発売されたChromeプロセスには適用されず、テストツールとスクリプトとの互換性が確保されます。
New Check Added
新しいチェックが追加されました
To detect when elevated privileges aren’t needed, Chrome now uses a new check called (UserAccountIsUnnecessarilyElevated) that identifies situations where User Account Control (UAC) is enabled, yet the browser is still running with an elevated, linked token — prompting Chrome to relaunch with standard permissions.
高度な特権が必要なときに検出するために、Chromeはユーザーアカウントコントロール(UAC)が有効になっている状況を識別する(UserAccountunnnnnecresillyNealElevated)と呼ばれる新しいチェックを使用しますが、ブラウザはまだ上昇したリンクされたトークンで実行されています。
Additionally, the RunDeElevatedNoWait function has been modified to accept the current working directory, which addresses issues where the default directory (typically system32), which previously led to unexpected or buggy behaviour in some scenarios.
さらに、RunDeelevatedNowait関数は、現在の作業ディレクトリを受け入れるように変更されています。これは、以前にいくつかのシナリオで予期しないまたはバグのような動作につながったデフォルトのディレクトリ(通常System32)に対処します。
With this initiative, the Chromium team warns about the security risks and compatibility issues that could arise from running with administrative rights. By defaulting to standard privileges, Chrome is looking to follow a safer, more user-friendly model, making the browser more robust in today’s increasingly complex digital landscape.
このイニシアチブにより、Chromiumチームは、管理権とともに実行することで生じる可能性のあるセキュリティリスクと互換性の問題について警告しています。デフォルトでは、標準的な特権に向けて、Chromeはより安全でユーザーフレンドリーなモデルに従うことを目指しており、今日のますます複雑なデジタルランドスケープでブラウザをより堅牢にしています。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































