Manually Installing the Widevine DRM Component for Chromium Browsers

Contents

Chrome and Edge ship with Widevine; Helium, ungoogled-chromium, and similar builds don’t, so DRM-protected sites simply refuse to play. The cause is Google’s licensing policy: certification costs on the order of ten thousand dollars, and Helium chose not to bundle the component (official FAQ, issue #116). The common workaround online is to install Chrome and copy the component out of it, but the very same component package can be downloaded straight from Google’s CDN. The method works for every Chromium-based browser; only the final destination directory differs.

Downloading the component

The component packages are Google’s, and Google publishes no direct download links. Mozilla maintains a manifest pointing at them in the Firefox source tree: gmp-sources/widevinecdm.json lists the download URL and SHA-512 checksum for every platform, and Firefox fetches its own DRM component from this manifest. The packages are hosted on Google’s CDN (edgedl.me.gvt1.com). The platform key is WINNT_x86_64-msvc for 64-bit Windows and Linux_x86_64-gcc3 for Linux.

Unpacking the crx3

The manifest points to a .crx3 file: the first 12 bytes are the Cr24 magic, a version number, and the header length, followed by a protobuf header, then a plain zip. Skip 12 + header length bytes and unzip the rest to get manifest.json plus the platform subdirectory (_platform_specific/win_x64/widevinecdm.dll on win64).

The whole flow in PowerShell:

$json = Invoke-RestMethod 'https://raw.githubusercontent.com/mozilla-firefox/firefox/refs/heads/main/toolkit/content/gmp-sources/widevinecdm.json'
$p = $json.vendors.'gmp-widevinecdm'.platforms.'WINNT_x86_64-msvc'

Invoke-WebRequest $p.fileUrl -OutFile "$env:TEMP\widevine.crx3"
(Get-FileHash "$env:TEMP\widevine.crx3" -Algorithm SHA512).Hash.ToLower() -eq $p.hashValue   # should print True

$b = [IO.File]::ReadAllBytes("$env:TEMP\widevine.crx3")
$hlen = [BitConverter]::ToUInt32($b, 8)
[IO.File]::WriteAllBytes("$env:TEMP\widevine.zip", $b[(12 + $hlen)..($b.Length - 1)])
Expand-Archive "$env:TEMP\widevine.zip" "$env:TEMP\widevine"
(Get-Content "$env:TEMP\widevine\manifest.json" | ConvertFrom-Json).version   # e.g. 4.10.3050.0

Where to put it

Chromium’s component scanner looks in two places: the browser install directory (wiped on upgrade) and the user data directory. Use the user data directory so it survives updates:

%LOCALAPPDATA%\<brand directory>\User Data\WidevineCdm\<component version>\

For Helium that’s %LOCALAPPDATA%\imput\Helium\User Data\WidevineCdm\4.10.3050.0\. The brand directory differs per browser: Google Chrome uses Google\Chrome, while Chromium itself has a single-level Chromium. If unsure, open chrome://version in the browser, find the Profile Path line, and copy everything before User Data.

Name the version subdirectory after the value read from the manifest, and extract the crx3 payload into it as-is (keep manifest.json and the whole _platform_specific directory). The scanner only enumerates subdirectories whose names parse as version numbers; files laid flat directly under WidevineCdm are ignored.

$v = (Get-Content "$env:TEMP\widevine\manifest.json" | ConvertFrom-Json).version
$dest = "$env:LOCALAPPDATA\imput\Helium\User Data\WidevineCdm\$v"   # replace with your browser's path
New-Item $dest -ItemType Directory -Force
Copy-Item "$env:TEMP\widevine\*" $dest -Recurse -Force

Verifying

Fully quit the browser (system tray included) and start it again, then open chrome://components (some forks rename the scheme, e.g. helium://components). Widevine Content Decryption Module showing 4.10.3050.0 instead of 0.0.0.0 means it’s registered. For a playback test, use bitmovin’s DRM demo.

L3 sites like Spotify’s web player and Bilibili play normally; Netflix, Disney+, and other services that require L1 hardware-level security (VMP) still refuse. That’s a certification-tier gap, not a component problem. Other users in issue #116 tested Helium and got the same result: HBO and Hulu play, Netflix doesn’t.

The CDM’s interface versions (4/10/10) have been stable for years, so browser upgrades don’t require reinstalling the component; when Google ships a new component version, just rerun the script above.

Edit this page

Contents