Vulnerabilities

Chrome 155 Update Patches 247 Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Chrome security

Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws.

All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.

The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher.

The fresh Chrome update resolves 53 high-severity vulnerabilities, including 34 reported by external researchers, Google notes in its advisory.

Approximately a dozen of these flaws were reported by Xinyang Ge. Many were found using AI, and Google will not reward the researcher for some of them.

The remaining 190 security defects are medium- and low-severity issues, most of which were discovered by Google.

Advertisement. Scroll to continue reading.

External security researchers reported a total of 62 of the bugs patched in this Chrome update. Google paid roughly $33,000 in bug bounty rewards, but has yet to disclose the amounts handed out for almost 50 of the reports.

The most common types of vulnerabilities resolved include incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17), uninitialized resource (16), confused deputy (9), and improper input validation (9).

Google makes no mention of any of these vulnerabilities being exploited in the wild.

The latest Chrome iteration is now rolling out to users as versions 155.0.8059.39/.40 for Windows and macOS, and as version 155.0.8059.39 for Linux.

Related: Android’s October 2026 Updates Patch 25 Vulnerabilities

Related: Atlassian Patches Critical Vulnerability Affecting 8 Products

Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Related: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

Related Content

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Vulnerabilities

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

Vulnerabilities

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

Vulnerabilities

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

Vulnerabilities

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Vulnerabilities

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Artificial Intelligence

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version