Chrome 155 fixes 247 security flaws, including four critical use-after-free bugs

Google has released Chrome 155 with patches for 247 vulnerabilities, four of them rated critical. There is no evidence any of the flaws are exploited in the wild.

Chrome 155 fixes 247 security flaws, including four critical use-after-free bugs

At a glance

  • Chrome 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux fix 247 security defects.
  • Four critical use-after-free flaws affect the Chromecast, Browser, Navigation and Track components.
  • 53 high-severity and 190 medium or low-severity issues were also fixed.
  • Google reported no evidence of in-the-wild exploitation.

Google has released Chrome 155 to the stable channel with fixes for 247 security vulnerabilities, including four rated critical, according to SecurityWeek. The update, published on Tuesday, rolls out as version 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux. Google reported no evidence that any of the flaws are being exploited in the wild, but the size of the release and the number of memory safety bugs make prompt updating advisable for both home users and organizations.

What was fixed

All four critical-severity bugs are use-after-free issues, SecurityWeek reported. They are tracked as CVE-2026-106382 in Chromecast, CVE-2026-106197 in the Browser component, CVE-2026-106358 in Navigation and CVE-2026-106347 in Track. Use-after-free flaws in browsers can potentially be chained with other bugs to execute code, which is why they typically receive high ratings.

Google found the first critical flaw internally. The other three were reported by researcher Xinyang Ge, who used AI assistance to identify two of them, according to SecurityWeek. Google has not yet announced bounty amounts for these reports.

The release also resolves 53 high-severity vulnerabilities, 34 of which were reported by external researchers. About a dozen of these came from Xinyang Ge, many found with the help of AI, and SecurityWeek said Google indicated it will not pay bounties for some of these findings. The remaining 190 flaws are medium or low severity and were mostly found by Google's own staff.

Technical details

According to SecurityWeek, the most common types of defects addressed in Chrome 155 are incorrect authorization (41 instances), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leaks (17), uninitialized resources (16), confused deputy issues (9) and improper input validation (9). External researchers submitted 62 of the bugs fixed in this release and received about $33,000 in combined bounties, though amounts for nearly 50 reports have not been disclosed.

What to do

Chrome updates automatically, but the new version only takes effect after the browser restarts. Users can check their version and trigger an update from the About Google Chrome page. Organizations managing Chrome centrally should push version 155 to endpoints and confirm that browsers have restarted. Users of other Chromium-based browsers should watch for corresponding updates from their vendors.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.