ZeroHour

CVE-2026-85043

mass

Incomplete Cleanup Access-Restriction Bypass in Google Chrome (CVE-2026-85043)

CVSS 3.1
9.1 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

Google Chrome contains an incomplete cleanup flaw (CWE-459) in its Network component, in which network resources are not properly cleaned up, allowing system access restrictions to be bypassed. A remote attacker can trigger the issue with crafted network traffic, requiring no privileges and no user interaction. Successful exploitation allows the attacker to bypass system access restrictions, and the 9.1 (Critical) CVSS score reflects high impact to confidentiality and availability. All users running Google Chrome prior to 152.0.7977.82 are affected, which given Chrome's install base is an extremely large population. No public proof-of-concept or KEV listing exists for this specific flaw and EPSS is low (0.3%), although a related Chrome zero-day (CVE-2026-85046) is reported exploited in the wild.

What to do: Update Google Chrome to 152.0.7977.82 or later (verify via chrome://settings/help) and prioritize managed fleets, shared/browsing kiosks, and high-risk users, since the attack requires no user interaction and no workaround exists for a network-stack flaw. Push the update via enterprise browser-update policies rather than relying on user action. Also confirm your deployed build addresses the related Chrome zero-day CVE-2026-85046, which is reported exploited in the wild.

Affected
Google Chromeall versions prior to 152.0.7977.82
Estimated exposure
mass≈3+ billion users (Chrome's global install base) — Chrome is the world's dominant desktop and mobile browser with an estimated 3+ billion users, and every installation on a version before 152.0.7977.82 remains affected until it is updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-459
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.