Kiosk mode Chrome escape via notification bar Share action: disable Notification Bar in Blueprint to block unrestricted browsing
Android
If you're running a device in Kiosk Mode with Google Chrome displaying a web app, users may be able to pull down the notification bar and use Chrome's share feature to open a new tab and browse unrestricted websites. This article explains how to block this behavior by disabling the notification bar in your Blueprint.
Before you begin
This issue occurs only when:
- Your device is in Kiosk Mode (not Multi-App Mode) with Google Chrome configured as the kiosk app
- The Notification Bar setting in your Blueprint is not explicitly disabled
- A user physically interacts with the device to pull down the notification bar
The issue cannot be reproduced through a remote session — it requires physical device interaction.
How to disable the notification bar
- In the Esper Console, go to Blueprints.
- Create a new Blueprint or edit the existing one assigned to your affected device group.
- Locate the Notification Bar setting in the Blueprint configuration.
- Set Notification Bar to Disabled.
- Click Save.
- Assign the updated Blueprint to your device(s): navigate to Devices & Groups → [Device Name] → Blueprint → Apply and select the updated Blueprint.
- Wait for the Blueprint to converge on the device.
How to verify the fix
After the Blueprint converges, physically test the device:
- Attempt to pull down the notification bar. It should now be fully suppressed.
- In Chrome, long-press a page element to open the context menu.
- Try selecting Share, Print, or Download. No new tab should open, and no navigation should occur.
If the issue persists
- Confirm Blueprint assignment: Check the device's Blueprint status in the Esper Console to verify the correct Blueprint (with Notification Bar disabled) is assigned and has finished converging.
- Collect a bug report: Go to Devices & Groups → [Device Name] → Actions → Bug Report and review the device logs for Blueprint application errors.
- Try an alternative browser: If Chrome's context menu continues to open new tabs despite the Notification Bar being disabled, consider replacing Chrome with a dedicated kiosk browser application that does not expose a share or navigation escape path. You can also apply additional app restrictions through Managed Configurations on the Chrome app.
Important notes
- The default Notification Bar setting in Kiosk Mode is not sufficient to prevent this behavior — you must explicitly set it to Disabled in your Blueprint.
- Even with the Notification Bar disabled, the Chrome long-press context menu may still visually appear, but selecting any action will produce no result. This is expected behavior.
- This issue is specific to Google Chrome. Other kiosk browsers may not expose the same vulnerability.
Still need help?
If you've followed these steps and the issue persists, contact Esper Support. include a video recording of the exact interaction sequence on your device if possible.
0
Please sign in to leave a comment.
Comments
0 comments