Chrome 155 Update Patches 247 Vulnerabilities
Google's Chrome 155 update patches 247 vulnerabilities, including four critical use-after-free flaws; no exploitation in the wild was reported.
Google's Chrome 155 security update resolves 247 vulnerabilities, including four critical use-after-free flaws tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347 affecting the Chromecast, Browser, Navigation, and Track components. Researcher Xinyang Ge reported three of the critical bugs and roughly a dozen of the 53 high-severity flaws, many found using AI. External researchers reported 62 bugs total, earning about $33,000 in bounties. Google mentions no in-the-wild exploitation; the update rolls out as version 155.0.8059.39/.40 for Windows and macOS.
- Four critical use-after-free flaws affect Chromecast, Browser, Navigation, and Track components
- Researcher Xinyang Ge used AI to find many flaws, including two critical ones
- 53 high-severity bugs fixed; 34 reported by external researchers
- Google paid roughly $33,000 in bounties; amounts for ~50 reports undisclosed
- No in-the-wild exploitation reported
Vulnerabilities mentionedAll →
- CVE-2026-1061979.6—Use-after-free sandbox escape in Google Chromepublished · Google Chrome+3 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-106197+3 related CVEs | Use-after-free sandbox escape in Google Chrome A use-after-free flaw (CWE-416) in the Browser component of Google Chrome, fixed in 155.0.8059.39, lets a remote attacker run arbitrary code outside the sandbox. The attacker needs the victim to open a crafted HTML page; no privileges are required, and Chromium rates the issue Critical (CVSS 3.1 base score 9.6, with changed scope and high impact on confidentiality, integrity, and availability). Anyone running Google Chrome older than 155.0.8059.39 is affected. It is not listed in CISA’s Known Exploited Vulnerabilities catalog, and no public proof-of-concept is known. |
Full article297 words · extracted from securityweek.com · click to collapse
Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws.
All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.
The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher.
The fresh Chrome update resolves 53 high-severity vulnerabilities, including 34 reported by external researchers, Google notes in its advisory.
Approximately a dozen of these flaws were reported by Xinyang Ge. Many were found using AI, and Google will not reward the researcher for some of them.
The remaining 190 security defects are medium- and low-severity issues, most of which were discovered by Google.
Advertisement. Scroll to continue reading.
External security researchers reported a total of 62 of the bugs patched in this Chrome update. Google paid roughly $33,000 in bug bounty rewards, but has yet to disclose the amounts handed out for almost 50 of the reports.
The most common types of vulnerabilities resolved include incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17), uninitialized resource (16), confused deputy (9), and improper input validation (9).
Google makes no mention of any of these vulnerabilities being exploited in the wild.
The latest Chrome iteration is now rolling out to users as versions 155.0.8059.39/.40 for Windows and macOS, and as version 155.0.8059.39 for Linux.
Related: Android’s October 2026 Updates Patch 25 Vulnerabilities
Related: Atlassian Patches Critical Vulnerability Affecting 8 Products
Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Related: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI