Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws
Google patched 247 Chrome flaws, including four critical use-after-free bugs, in version 155.0.8059.39.
On October 6, 2026, Google shipped Chrome 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux, fixing 247 vulnerabilities. Four critical issues are use-after-free bugs: CVE-2026-106382 in Chromecast, CVE-2026-106197 in Browser, CVE-2026-106358 in Navigation, and CVE-2026-106347 in Track. Google does not describe exploit methods, confirm arbitrary code execution, or say the flaws are exploited in the wild. High-severity fixes include CVE-2026-102322 (incorrect authorization in Site Isolation) and CVE-2026-106239 (integer overflow in WebGL), plus issues in ANGLE, V8, WebRTC, and other components.
- Chrome 155.0.8059.39/.40 fixes 247 flaws on Windows, Mac, and Linux.
- Four critical bugs are use-after-free issues in Chromecast, Browser, Navigation, and Track.
- Google does not report exploitation or confirm sandbox escape.
- Xinyang Ge of Anthropic, assisted by Claude, reported two critical flaws.
- High-severity fixes also cover Site Isolation, WebGL, ANGLE, and V8.
Vulnerabilities mentionedAll →
- CVE-2026-1023229.6—Incorrect authorization RCE in Google Chrome Site Isolationpublished · Google Chrome+5 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102322 |
Full article499 words · extracted from cybersecuritynews.com · click to collapse
Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws, across Windows, Mac, and Linux.
The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google’s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution.
The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the use-after-free issue on July 15, 2026. The second, CVE-2026-106197, affects the Browser component and security researcher Xinyang Ge reported on September 11, 2026.
CVE-2026-106358 affects Navigation and was reported on September 28, 2026. CVE-2026-106347 affects Track and was reported on September 30, 2026.
Google credits Xinyang Ge of Anthropic, assisted by Claude, for both discoveries, highlighting AI assistance in the vulnerability research process.
All 4 critical entries share the same underlying weakness category: use-after-free. This category concerns software accessing memory after it has been released.
Critical Flaws :
| CVE | Affected component | Vulnerability | Reported by |
|---|---|---|---|
| CVE-2026-106382 | Chromecast | Use after free | |
| CVE-2026-106197 | Browser | Use after free | Xinyang Ge |
| CVE-2026-106358 | Navigation | Use after free | Xinyang Ge, Anthropic, assisted by Claude |
| CVE-2026-106347 | Track | Use after free | Xinyang Ge, Anthropic, assisted by Claude |
However, the advisory does not establish whether these particular flaws permit a sandbox escape, require user interaction, or can be combined into a working attack chain.
Chrome Update Fixes Massive 247 Vulnerabilities
Google has not explicitly stated that these vulnerabilities are being exploited in the wild. That absence should not be interpreted as proof that exploitation has never occurred.
The update also addresses high severity flaws across graphics, media, browser interfaces, and security controls. CVE-2026-102322 involves incorrect authorization in SiteIsolation, while CVE-2026-106239 concerns an integer overflow in WebGL. Several ANGLE vulnerabilities involve uninitialized resources, alongside type confusion and use-after-free issues.
The V8 engine receives fixes for race conditions, type confusion, and use-after-free. Other affected components include WebRTC, WebAudio, PDF, Storage, Autofill, Fonts, and DevTools. Medium- and low-severity entries cover information leaks, missing authorization, misleading interfaces, and additional resource-handling weaknesses.
Google says many security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. These tools form part of the company’s broader security testing effort.
Google warns that access to bug details may remain restricted until most users have installed fixes. Restrictions can also continue when a vulnerability affects a third-party library used by other projects that have not yet patched it.
For organizations tracking remediation, the announced version numbers provide a clear reference for checking deployment progress. The staged rollout means availability may differ between systems. Security teams should distinguish the confirmed fixes from unverified claims about exploitability when communicating this release’s risk to users and administrators.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.