Chrome 155 Patches 247 Vulnerabilities
The update closes four critical use-after-free flaws that could let attackers run code outside Chrome’s sandbox.
Overview
- Google rolled out Chrome 155 on Tuesday with builds 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux while Android received a limited release.
- The advisory identifies four critical use-after-free bugs — CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347 — affecting Chromecast, Browser, Navigation, and Track components.
- Google says none of the patched vulnerabilities are known to have been exploited in the wild and the update also resolves 53 high-severity and many medium- and low-severity flaws.
- External researchers reported 62 of the issues, with Xinyang Ge credited for roughly a dozen findings that included some discovered using AI, and Google reported paying about $33,000 in bounties while limiting rewards for certain AI-generated reports.
- Users should update or restart Chrome now because automatic updates can lag if the browser remains open or extensions interfere, and prompt patching is the best defense given Chrome’s frequent large security releases.