TL;DR
Google has promoted Chrome 155 to the Stable channel with 247 security fixes. The Chrome 155 security update patches four Critical use-after-free bugs and at least 53 High-severity flaws. Google has not reported any of them as exploited in the wild.
- Total: 6 CVEs
- Severity: 4 Critical · 2 High
- Actively exploited: None confirmed
- Highest severity: 9.6 (Critical · CVSSv3) — CVE-2026-106382
- Action: Apply the latest security updates now
Tired of noisy Google CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-106382 | 9.6 | CWE-416 | 155.0.8059.39 | Not exploited |
| CVE-2026-106197 | 9.6 | CWE-416 | 155.0.8059.39 | Not exploited |
| CVE-2026-106358 | 9.6 | CWE-416 | 155.0.8059.39 | Not exploited |
| CVE-2026-102322 | 9.6 | CWE-863 | 155.0.8059.39 | Not exploited |
| CVE-2026-106347 | 8.8 | CWE-416 | 155.0.8059.39 | Not exploited |
| CVE-2026-106240 | 8.8 | CWE-843 | 155.0.8059.39 | Not exploited |
Why It Matters
A batch of 247 fixes is unusually large for one browser release. Chrome runs on billions of devices, so each memory bug is a wide target. Most of these flaws sit in code that handles web content, which any site can reach.
Google is also keeping details private for now. The Chrome Stable channel release notes explain that “access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
The credits show a clear trend. Twelve entries name Xinyang Ge of Anthropic, “assisted by Claude.” Two more come from OpenAI Codex Security. As a result, AI-assisted research now accounts for a visible share of Chrome’s bug reports.
How the Attacks Work
Critical Use-After-Free Flaws
All four Critical bugs are use-after-free errors. This class of bug occurs when code keeps using memory after it has been released. An attacker who controls that memory can often corrupt data or run code.
- CVE-2026-106382: use after free in Chromecast, reported by Google
- CVE-2026-106197: use after free in Browser, reported by Xinyang Ge
- CVE-2026-106358: use after free in Navigation, reported by Xinyang Ge (Anthropic), assisted by Claude
- CVE-2026-106347: use after free in Track, reported by Xinyang Ge (Anthropic), assisted by Claude
Notable High-Severity Bugs
Among the High-rated issues, CVE-2026-102322 earned the top listed bounty of $5,000. It is an incorrect authorization flaw in Site Isolation, a core sandbox defense. Meanwhile, CVE-2026-106240 is a type confusion bug in the V8 JavaScript engine. Other flaws hit ANGLE, WebRTC, Media, PDF and Autofill.
Affected Versions
Every Chrome build before this release is affected. The fixed versions are:
- Windows and Mac: 155.0.8059.39/.40
- Linux: 155.0.8059.39
Google says the rollout will happen “over the coming days/weeks.” Other Chromium-based browsers will need their own patches.
Patch and Mitigation Steps
Install the Chrome 155 security update now rather than waiting for the automatic rollout. Open the menu, go to Help, and choose About Google Chrome. Chrome will download the new build. Then restart the browser to finish the update.
Admins should push the release through their management tools. In addition, check Edge, Brave and Opera for matching updates once their vendors ship them.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!