CVE-2026-85043

Google · Chrome

An incomplete cleanup vulnerability in the Google Chrome network stack allows a remote, unauthenticated attacker to bypass system access restrictions using crafted network traffic.

Executive summary

A critical vulnerability in Google Chrome allows remote, unauthenticated attackers to bypass system security restrictions, posing a significant risk to data confidentiality and system availability.

Vulnerability

This flaw, categorized as CWE-459 (Incomplete Cleanup), exists within the network component of the browser. It allows an unauthenticated remote attacker to trigger restricted system actions by sending specifically crafted network traffic to the target application.

Business impact

The exploitation of this vulnerability carries a high risk of unauthorized data access and potential service disruption. With a CVSS score of 9.1, this flaw is classified as critical because it is remotely exploitable without requiring user interaction or authentication, which could lead to significant data exposure or loss of system integrity.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.82 or later immediately to apply the necessary security patches.

Proactive Monitoring: Review network access logs for anomalous traffic patterns or unexpected connections originating from external or untrusted sources.

Compensating Controls: Ensure that endpoint security solutions and intrusion detection systems are active to identify and block malformed network packets that may attempt to exploit known network stack vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the ease of exploitation over the network, organizations must prioritize updating Google Chrome across all managed environments. Administrators should verify successful deployment of the version 152.0.7977.82 patch and ensure that legacy, unpatched versions are removed from the network to minimize the attack surface.

More Google CVEs all →

Sources