How to prevent Progressive Web Apps (PWAs) from installing on your desktop.
A PWA is a web-based app created using HTML, CSS, and JavaScript that can be installed from a website like a regular desktop application. Once installed, the operating system will create a PWA shortcut and add it to Add or Remove Programs in Windows and under the /Users/<account>/Applications/ folder in macOS.
Recently these have been used to steal credentials and are unsafe.
New phishing toolkit uses PWAs to steal login credentials (bleepingcomputer.com)
In Edge, type in address bar about://flags, search for 'handling' and change the settings to match image below. All settings that required changes are now all changed to Disabled.
about://settings, search for 'application'
Change to off position as in image below.
about://settings, search for 'protocol'
Change to off position as in image below.
about://settings, search for 'apps'
Turn on Block Potentially Unwanted Apps.
Microsoft Defender SmartScreen must be enabled to turn on Block Potentially Unwanted Apps.
But note MDSS, talks to Microsoft servers, and is a privacy leak.
PWAs as URL Handlers | Capabilities | Chrome for Developers
Handle protocols in Progressive Web Apps - Microsoft Edge Developer documentation | Microsoft Learn
Test PWA -
No comments:
Post a Comment