AI analysis
Google Chrome contains an incomplete cleanup flaw (CWE-459) in its Network component, in which network resources are not properly cleaned up, allowing system access restrictions to be bypassed. A remote attacker can trigger the issue with crafted network traffic, requiring no privileges and no user interaction. Successful exploitation allows the attacker to bypass system access restrictions, and the 9.1 (Critical) CVSS score reflects high impact to confidentiality and availability. All users running Google Chrome prior to 152.0.7977.82 are affected, which given Chrome's install base is an extremely large population. No public proof-of-concept or KEV listing exists for this specific flaw and EPSS is low (0.3%), although a related Chrome zero-day (CVE-2026-85046) is reported exploited in the wild.
What to do: Update Google Chrome to 152.0.7977.82 or later (verify via chrome://settings/help) and prioritize managed fleets, shared/browsing kiosks, and high-risk users, since the attack requires no user interaction and no workaround exists for a network-stack flaw. Push the update via enterprise browser-update policies rather than relying on user action. Also confirm your deployed build addresses the related Chrome zero-day CVE-2026-85046, which is reported exploited in the wild.
Affected
| Google Chrome | all versions prior to 152.0.7977.82 |
Estimated exposure
mass≈3+ billion users (Chrome's global install base) — Chrome is the world's dominant desktop and mobile browser with an estimated 3+ billion users, and every installation on a version before 152.0.7977.82 remains affected until it is updated.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.