Chrome 155 fixes 247 flaws; Canada urges patching
Google's October 6 Chrome update fixes 247 flaws, including four critical use-after-free bugs; Canada urged users to install the new builds.
On October 6, 2026, Google shipped a Chrome stable update fixing 247 vulnerabilities, including four critical use-after-free bugs: CVE-2026-106382 in Chromecast, CVE-2026-106197 in Browser, CVE-2026-106358 in Navigation, and CVE-2026-106347 in Track. Cyber Security News, SecurityWeek, and Canada's Cyber Centre identify Windows and Mac builds as 155.0.8059.39/.40 and Linux as 155.0.8059.39, while Malwarebytes lists Windows and Mac as 154.0.8037.39/.40, Linux as 155.0.8059.39, and a gradual Android rollout of 155.0.8059.39. Malwarebytes says the Browser and Navigation bugs could let a remote attacker run code outside the sandbox via crafted HTML, but Cyber Security News says Google does not confirm arbitrary code execution or a sandbox escape and does not describe exploit methods; no report says any flaw is exploited in the wild. SecurityWeek adds 53 high-severity fixes, 62 externally reported bugs, and about $33,000 in bounties, while other high-severity items named are CVE-2026-102322, CVE-2026-106239, and CVE-2026-106240. Credit for researcher Xinyang Ge differs: two critical flaws, with Anthropic and Claude assistance, in Cyber Security News, versus three critical bugs in SecurityWeek's summary and two in its points, many found using AI. On October 7, the Canadian Centre for Cyber Security issued advisory AV26-1006 urging users and administrators to install the update; the notice names no CVEs.
- On October 6, 2026, Google's Chrome stable update fixed 247 vulnerabilities, including four critical use-after-free bugs: CVE-2026-106382 (Chromecast), CVE-2026-106197 (Browser), CVE-2026-106358 (Navigation), and CVE-2026-106347 (Track).
- Cyber Security News, SecurityWeek, and Canada's Cyber Centre identify Windows and Mac as 155.0.8059.39/.40 and Linux as 155.0.8059.39; Malwarebytes instead lists Windows and Mac as 154.0.8037.39/.40, Linux as 155.0.8059.39, and a gradual…
- Malwarebytes says CVE-2026-106197 and CVE-2026-106358 could let a remote attacker run code outside the sandbox via crafted HTML; Cyber Security News says Google does not confirm arbitrary code execution or a sandbox escape and does not…
- No source reports in-the-wild exploitation.
- Named high-severity issues include CVE-2026-102322 (incorrect authorization in Site Isolation), CVE-2026-106239 (integer overflow in WebGL), and CVE-2026-106240 (V8 type confusion that could execute code inside the sandbox).
- SecurityWeek reports 53 high-severity fixes, 62 externally reported bugs, and about $33,000 in bounties; Xinyang Ge credit differs (two critical flaws, with Anthropic and Claude assistance, versus three in SecurityWeek's summary and two in…
Coverage timelineoldest first · each row is one article
- · 1d agoGoogle Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws
Cyber Security News· 67
Google patched 247 Chrome flaws, including four critical use-after-free bugs, in version 155.0.8059.39.
- · 1d agoUpdate Chrome and ChromeOS to fix critical security issues
Malwarebytes Labs· 68
Google patched Chrome and ChromeOS, including critical sandbox-escape use-after-free bugs.
- · 1d agoChrome 155 Update Patches 247 Vulnerabilities
SecurityWeek· 58
Google's Chrome 155 update patches 247 vulnerabilities, including four critical use-after-free flaws; no exploitation in the wild was reported.
Vulnerabilities in this storyAll →
- CVE-2026-1023229.6—Incorrect authorization RCE in Google Chrome Site Isolationpublished · Google Chrome+6 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102322 |