IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Chrome Updater Not Working

App Control: Chrome Updater Not Working

Environment

  • App Control Server: All Supported Versions
  • App Control Agent: All Supported Versions
  • Microsoft Windows: All Supported Versions

Symptoms

  • Chrome Updater (Rules > Software Rules > Updaters > Google Chrome) is already enabled.
  • New Unapproved File Events similar to:
    Computer computer discovered new file c:\windows\systemtemp\chrome_unpacker_beginunzipping...\VERSION_chrome_updater.exe [HASH]. DiscoveredBy[Kernel:Create]
  • Block Events similar to:
    File c:\windows\systemtemp\chrome_unpacker_beginunzipping...\VERSION_chrome_updater.exe [HASH] was blocked because it was unapproved.

Cause

The Process and File Path combination the Chrome Updater is looking for has changed.

Resolution

This issue is being investigated by Engineering (EP-20312), but in the meantime there are multiple options to workaround this issue:
  • Approve the Publisher, Google LLC in Rules > Software Rules > Publishers.
  • Create a File Creation Control Rule to use while Engineering investigates the issue:
    1. Log in to the Console and navigate to Rules > Software Rules > Custom > Add Custom Rule.
    2.  Use the following details:
      • Rule Name: Temp - Chrome Updater
      • Description: Workaround during EP-20312
      • Status: Enabled
      • Platform: Windows
      • Rule Type: File Creation Control
      • Write Action: Approve as installer
      • Path:
        <Windows>\systemtemp\chrome_*\*chrome_updater.exe
        <Windows>\systemtemp\chrome_*\*chrome_installer.exe
        
      • Process: 
        <ProgramFilesx86>\Google\GoogleUpdater\*\updater.exe
      • User or Group: Local System
      • Policies: Choose relevant Policies
    3. Click Save & Exit

Additional Notes

  • In some instances the Chrome updates can be managed via GPO and the path of the new files may differ slightly from the above. 
  • Using the Saved View, New Files (All) in Reports > Events may assist in confirming expected File Paths.
  • File Creation Control Rules require the Agent to observe the Process specified writing files that match the Path specified.
  • Existing files will need to either be rewritten or manually issued a Local or Global Approval.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-24-2024
Views:
674
Contributors