Google shipped Chrome 155 on 6 October 2026 with fixes for 247 vulnerabilities. Four are critical use-after-free bugs. Google has not said any of them are being exploited.
What happened
The four critical issues sit in Chromecast, Browser, Navigation, and Track. They are CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. Google found the first. Researcher Xinyang Ge reported the other three, and used AI to find two of them.
Another 53 flaws are high severity, 34 of those from outside Google. The remaining 190 are medium or low. External researchers reported 62 bugs in this release. Disclosed bounty payments so far are about $33,000, with many amounts still unpublished. The common classes are incorrect authorization, use-after-free, and missing authorization.
Who is affected
Desktop Chrome on Windows, macOS, and Linux is the rollout SecurityWeek described. Fixed builds are 155.0.8059.39 and 155.0.8059.40 on Windows and macOS, and 155.0.8059.39 on Linux. Managed fleets that pin an older channel, or that rely on users to relaunch, will stay exposed after the bits are downloaded.
- Windows and macOS: 155.0.8059.39 or 155.0.8059.40
- Linux: 155.0.8059.39
- Any kiosk, VDI image, or jump host that does not auto-relaunch Chrome
What to do now
Confirm the running version, not just the downloaded one, then relaunch. In a managed estate, push 155 and check that sessions actually restarted. There is no public report of exploitation, but a 247-fix release with four critical use-after-free bugs should not sit in a pending-restart queue.
Source: SecurityWeek, Chrome 155 Update Patches 247 Vulnerabilities.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 FortiGate devices still locked out
- tensorlake 0.5.144: npm worm steals cloud and AI-tool credentials
- CVE-2026-102255: SonicWall SMA1000 SSRF scores CVSS 10
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.