Zhipu's decision to open-source ZCode after a data-handling dispute and public apology is a trust-repair move as much as a technical one. Open code lets enterprises audit how a desktop, browser, and terminal-agent workbench touches their source, and the promised no-retention option on its MaaS platform is aimed squarely at the objection that kills most agentic-coding pilots: where does my proprietary code go, and who keeps it. Transparency plus verifiable data controls is fast becoming table stakes for any vendor selling AI that reads and writes production code.
But the story executives should not lose in the noise is the actively exploited Chromium sandbox-escape RCE affecting all Chromium-based versions. This is a live-fire event, not a theoretical CVE. The Chromium engine sits under Chrome, Edge, Brave, Electron desktop apps, and countless embedded webviews. A sandbox escape means a malicious page can break out of the browser's containment and reach the host, and 'actively exploited' means attackers are already using it in the wild. The patch window is now, not next sprint.
The uncomfortable link between these two items is agentic tooling itself. Coding agents like ZCode ship browser components and terminal access by design. A browser-engine escape in an autonomous agent that already has file-system and shell privileges is a far larger blast radius than the same flaw in a human-driven tab. As enterprises wire agents into their pipelines, the attack surface of the browser stack becomes the attack surface of the whole dev environment.
For Japanese enterprises and SIers, the Chromium flaw is the immediate action item. Fleets standardized on Edge or Chrome, plus the many in-house and packaged tools built on Electron, all inherit the exposure. SIers running managed desktop environments for financial and manufacturing clients should treat this as an emergency patch cycle and inventory every Electron-based application in their delivery portfolio, since those rarely auto-update in step with the browser.
Strategically, Zhipu's open-source-and-no-retention posture sets a bar Japanese buyers should apply to every AI coding vendor, domestic or foreign. Procurement teams at large SIers evaluating agentic tools should demand auditable code, contractual no-retention terms, and a clear answer on how the agent's embedded browser is sandboxed and patched. Data residency and China-vendor scrutiny will weigh on Zhipu adoption specifically, but the governance checklist it implies applies universally. The lesson for local dev teams: the convenience of agents that browse, code, and execute is inseparable from the security hygiene of the components underneath them.