Back to Feed
VulnerabilitiesOct 7, 2026

Chrome 155 Update Patches 247 Vulnerabilities

Chrome 155 update fixes 247 vulnerabilities, including four critical use-after-free flaws.

Summary

Google has released a Chrome 155 security update addressing 247 vulnerabilities, with four critical use-after-free defects impacting Chromecast, Browser, Navigation, and Track components. Researcher Xinyang Ge identified three of these critical flaws, two of which were found using AI. The update also resolves 53 high-severity vulnerabilities, with many also identified by Ge using AI, though Google will not reward the researcher for some of these AI-discovered issues.

Full text

Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws. All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher. The fresh Chrome update resolves 53 high-severity vulnerabilities, including 34 reported by external researchers, Google notes in its advisory. Approximately a dozen of these flaws were reported by Xinyang Ge. Many were found using AI, and Google will not reward the researcher for some of them. The remaining 190 security defects are medium- and low-severity issues, most of which were discovered by Google.Advertisement. Scroll to continue reading. External security researchers reported a total of 62 of the bugs patched in this Chrome update. Google paid roughly $33,000 in bug bounty rewards, but has yet to disclose the amounts handed out for almost 50 of the reports. The most common types of vulnerabilities resolved include incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17), uninitialized resource (16), confused deputy (9), and improper input validation (9). Google makes no mention of any of these vulnerabilities being exploited in the wild. The latest Chrome iteration is now rolling out to users as versions 155.0.8059.39/.40 for Windows and macOS, and as version 155.0.8059.39 for Linux. Related: Android’s October 2026 Updates Patch 25 Vulnerabilities Related: Atlassian Patches Critical Vulnerability Affecting 8 Products Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports Related: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksLong-Running NPM Malware Campaign Accumulates 40,000 Downloads8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare FirmsExploitation Hits Rejetto HFS Vulnerability Discovered by AI Alleged ShinyHunters Leader Arrested in JordanFortra Patches Critical Vulnerabilities in BoKS Latest News Anthropic Introduces 3-Tier Cyber Verification Program for AI AccessASOS Confirms Cyberattack, Data BreachWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsPersonal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court SystemFBI Blames Contractor’s Missed Patch for ShinyHunters BreachFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-106382
  • cve — CVE-2026-106197
  • cve — CVE-2026-106358
  • cve — CVE-2026-106347

Entities

Chrome (product)Google (vendor)AI (technology)