DIRAS TAKE
Urgent: apply the vendor fix 152.0.7977.82 immediately because this is a remotely reachable bypass that requires no authentication or user interaction.
What is CVE-2026-85043?
A remote attacker can bypass system access restrictions in Google Chrome via crafted network traffic, affecting Chrome versions in the 152.x branch prior to 152.0.7977.82 (CVE-2026-85043). The flaw arises from incomplete cleanup in the network component and can be triggered over the network without prior authentication or user interaction. Affected installations of Chrome 152.x should be updated because an attacker only needs network access to exploit this vulnerability.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.82 – before 152.0.7977.82 | 152.0.7977.82 |
Is CVE-2026-85043 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-85043
- Update Google Chrome to 152.0.7977.82 or later.
- Follow vendor guidance and apply the official security update on all endpoints.
- Restrict unnecessary network exposure of affected clients and enforce network segmentation.
- Monitor network and endpoint logs for unusual traffic patterns or crashes in the Chrome network component.
Frequently asked questions
Is CVE-2026-85043 being actively exploited?
There are no public reports of active exploitation of CVE-2026-85043 as of 2026-09-30.
Which Chrome versions are affected by CVE-2026-85043?
Chrome versions in the 152.x branch prior to 152.0.7977.82 are affected by CVE-2026-85043.
Is there a patch for CVE-2026-85043?
Yes. Google released a fix in Chrome version 152.0.7977.82.
Does CVE-2026-85043 require authentication?
No. The vulnerability can be triggered over the network without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85043
- cve.org/CVERecord?id=CVE-2026-85043
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
- issues.chromium.org/issues/533502257
- All Google CVEs on CVE Radar
- CVEs published in September 2026