• PATCH AVAILABLE

CVE-2026-85043: network access bypass in Google Chrome

A remote attacker can bypass system access restrictions in Google Chrome via crafted network traffic, affecting Chrome versions in the 152.x branch prior to 152.0.7977.82 (CVE-2026-85043). The flaw arises from incomplete cleanup in the network component and can be triggered over the network without prior authentication or user interaction. Affected installations of Chrome 152.x should be updated because an attacker only needs network access to exploit this vulnerability.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00441
CWE
CWE-459
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply the vendor fix 152.0.7977.82 immediately because this is a remotely reachable bypass that requires no authentication or user interaction.

What is CVE-2026-85043?

A remote attacker can bypass system access restrictions in Google Chrome via crafted network traffic, affecting Chrome versions in the 152.x branch prior to 152.0.7977.82 (CVE-2026-85043). The flaw arises from incomplete cleanup in the network component and can be triggered over the network without prior authentication or user interaction. Affected installations of Chrome 152.x should be updated because an attacker only needs network access to exploit this vulnerability.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.82 – before 152.0.7977.82152.0.7977.82

Is CVE-2026-85043 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-85043

  1. Update Google Chrome to 152.0.7977.82 or later.
  2. Follow vendor guidance and apply the official security update on all endpoints.
  3. Restrict unnecessary network exposure of affected clients and enforce network segmentation.
  4. Monitor network and endpoint logs for unusual traffic patterns or crashes in the Chrome network component.

Frequently asked questions

Is CVE-2026-85043 being actively exploited?

There are no public reports of active exploitation of CVE-2026-85043 as of 2026-09-30.

Which Chrome versions are affected by CVE-2026-85043?

Chrome versions in the 152.x branch prior to 152.0.7977.82 are affected by CVE-2026-85043.

Is there a patch for CVE-2026-85043?

Yes. Google released a fix in Chrome version 152.0.7977.82.

Does CVE-2026-85043 require authentication?

No. The vulnerability can be triggered over the network without authentication or user interaction.

References