Hi Fraud Defense team,
Starting 2026-07-17 (zero occurrences before that date), legitimate desktop
Chrome 150 users on our site began receiving very low reCAPTCHA Enterprise
scores (0.1-0.3) with reason code UNEXPECTED_ENVIRONMENT on our sign-in
action, blocking them from logging in. Tokens are fully valid and the action
matches the expected action -- only the risk score collapsed.
Setup: web score-based site key (v3-style), server-side assessments via the
reCAPTCHA Enterprise API. Users are mostly in Taiwan on residential ISPs.
Evidence that this is browser-version-specific
(rejected vs. allowed-with-low-score counts, same site key and threshold,
last 2 days):
- Chrome 150 desktop: 306 rejected / 22 allowed
- Chrome 149 desktop: 2 rejected / 23 allowed
- Edge (Chromium 150): 1 rejected / 4 allowed
Daily rejected count for Chrome 150: 0 (before Jul 17) -> 98 (Jul 17) ->
113 (Jul 18) -> 180 (Jul 19), still rising. Chrome 150 had already been
rolled out for about two weeks before Jul 17, so the sudden onset does not
follow the browser adoption curve -- it looks like a server-side risk model
change around Jul 16-17 misclassifying Chrome 150's environment signals.
Example user agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36
Impact: Chrome 150 is currently the most common desktop browser version
among our users, so this is blocking hundreds of legitimate sign-ins per
day and growing.
Could you please investigate whether a recent risk model update mis-scores
Chrome 150 desktop environments as UNEXPECTED_ENVIRONMENT? Similar
incidents were fixed server-side in mid-2025 (iOS browsers) and reported
again in May 2026 (mobile SDK traffic).
I can share the site key, project number, and sample assessment IDs
(with timestamps and scores) via private message. Thanks!
