Fleet-wide Chrome vulnerability exposure closed in one day
An EY security assessment flagged 529,644 Chrome vulnerabilities across 1,449 devices, 66% of everything it found. The cause was architectural. Two conflicting Chrome update rules in Workspace ONE pushed different versions to the same devices, and Chrome's built-in updater had silently stopped working on affected machines, in some cases for up to two years.
I removed the conflicting rules, cleaned duplicate and stale Chrome entries out of the device catalog, and put one enforced update policy in place fleet-wide, so Chrome updates no longer depend on the browser's own updater. I delivered an executive brief on the remediation to leadership.
Same day, devices on the fixed version went from 751 to 1,389 (43% to 80% of the 1,728 targeted), closing roughly 507,000 of the ~523,000 credited vulnerability instances.