Google has given Chrome users 247 new reasons to keep their browsers up to date.
The company released Chrome 155 with 247 security fixes, including four vulnerabilities rated Critical and another 53 rated High. The update is rolling out to Windows, macOS, and Linux users over the coming days and weeks, according to Google’s Chrome release notes.
None of the four Critical vulnerabilities are currently identified by Google as being exploited in the wild. But after a year in which attackers have repeatedly targeted Chrome vulnerabilities, the size and severity of this update give security teams another reason to verify that browser patches are actually reaching managed endpoints.
Four Critical Chrome flaws involve memory safety
The four Critical vulnerabilities are all use-after-free flaws, a class of memory-safety bugs that occur when software continues to access memory after it has been released.
Google identified the vulnerabilities as:
- CVE-2026-106382: Use-after-free vulnerability in Chromecast
- CVE-2026-106197: Use-after-free vulnerability in Browser
- CVE-2026-106358: Use-after-free vulnerability in Navigation
- CVE-2026-106347: Use-after-free vulnerability in Track
Use-after-free vulnerabilities can cause crashes and, depending on the affected component and the conditions under which an exploit is executed, may be leveraged for memory corruption or code execution. Google has not disclosed specific attack scenarios for these four flaws.
The vulnerabilities are especially noteworthy because they affect several different parts of Chrome. Google discovered CVE-2026-106382 internally, while researcher Xinyang Ge reported the other three.
Two of Ge’s Critical findings, CVE-2026-106358 and CVE-2026-106347, were discovered with assistance from Claude, according to Google’s advisory. Google identifies Ge as being with Anthropic.
The release also patches 53 High-severity vulnerabilities across a wide range of Chrome components, according to SecurityWeek’s count of Google’s advisory.
Google is restricting access to some vulnerability details until a majority of Chrome users have received the update, a practice designed to limit information that could help attackers target users who have not yet patched.
Chrome vulnerabilities have already been exploited this year
There is no indication so far that attackers are exploiting the four Critical vulnerabilities patched in Chrome 155. That distinction matters.
Chrome, however, has faced a steady stream of actively exploited vulnerabilities in 2026. In September, Google patched CVE-2026-85046 after confirming attackers were already exploiting the V8 vulnerability. It became the sixth Chrome zero-day known to have been exploited during the year.
Days later, another exploited Chrome vulnerability pushed that number to at least seven. Earlier attacks demonstrated how quickly browser vulnerabilities can become part of real-world campaigns.
One September campaign showed the potential consequences particularly clearly. Four espionage groups used the BlueMoon exploit kit to chain Chrome and Windows zero-days against organizations in the United States and Southeast Asia.
Chrome 155 also follows an unusually large security update just weeks earlier. Chrome 154 fixed 108 vulnerabilities, including 11 rated Critical.
The new release more than doubles that total with 247 security fixes, although vulnerability counts alone do not indicate how dangerous a browser release is. Severity, exploitability, exposure, and whether attackers are actively abusing a flaw are more important measures of immediate risk.
Security teams should verify Chrome 155 is actually installed
Chrome normally handles updates in the background, but users may need to relaunch the browser for a new version to take effect. In managed environments, administrators can also control how and when updates are deployed.
Google says Chrome 155 is rolling out as 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux.
Users can manually check their version by opening Chrome and navigating to Help > About Google Chrome. Chrome will check for available updates and prompt the user to relaunch when necessary.
For security administrators, the larger task is making sure updates have reached managed endpoints rather than assuming Chrome’s automatic updater has handled every device.
Organizations should:
- Check Chrome versions across managed Windows, macOS, and Linux endpoints.
- Identify devices still running older Chrome releases.
- Make sure users relaunch Chrome when required to complete an update.
- Review browser-update policies that may intentionally defer new versions.
- Continue monitoring Google’s advisories as more technical information about the vulnerabilities becomes available.
That last step matters because Google is still withholding some technical details while Chrome 155 rolls out.
Browser patching has become an increasingly important part of endpoint security. The important question for organizations is not simply how many vulnerabilities Chrome contains, but how quickly they close the window between a fix becoming available and that fix reaching users.
For security teams managing Chrome fleets, 247 fixes make that window difficult to ignore.
Read next: See the four security habits worth adopting in 2026, including why faster software patching matters as attackers move quickly to exploit new vulnerabilities.





