Google Chrome Update Fixes 247 Security Flaws, Including 4 Critical Bugs

Google Chrome 155 fixes 247 security vulnerabilities, including four Critical use-after-free flaws. See what security teams should do now.

Written By
Matt Gonzales
Matt Gonzales
Oct 7, 2026
4 minute read
Cracked Google Chrome logo lying on a dark surface surrounded by broken fragments.

A cracked Google Chrome logo represents the security risks addressed by the browser’s latest update, which patches 247 vulnerabilities. Image: Generated via Google’s Nano Banana

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Google has given Chrome users 247 new reasons to keep their browsers up to date.

The company released Chrome 155 with 247 security fixes, including four vulnerabilities rated Critical and another 53 rated High. The update is rolling out to Windows, macOS, and Linux users over the coming days and weeks, according to Google’s Chrome release notes.

None of the four Critical vulnerabilities are currently identified by Google as being exploited in the wild. But after a year in which attackers have repeatedly targeted Chrome vulnerabilities, the size and severity of this update give security teams another reason to verify that browser patches are actually reaching managed endpoints.

Four Critical Chrome flaws involve memory safety

The four Critical vulnerabilities are all use-after-free flaws, a class of memory-safety bugs that occur when software continues to access memory after it has been released.

Google identified the vulnerabilities as:

  • CVE-2026-106382: Use-after-free vulnerability in Chromecast
  • CVE-2026-106197: Use-after-free vulnerability in Browser
  • CVE-2026-106358: Use-after-free vulnerability in Navigation
  • CVE-2026-106347: Use-after-free vulnerability in Track

Use-after-free vulnerabilities can cause crashes and, depending on the affected component and the conditions under which an exploit is executed, may be leveraged for memory corruption or code execution. Google has not disclosed specific attack scenarios for these four flaws.

The vulnerabilities are especially noteworthy because they affect several different parts of Chrome. Google discovered CVE-2026-106382 internally, while researcher Xinyang Ge reported the other three.

Two of Ge’s Critical findings, CVE-2026-106358 and CVE-2026-106347, were discovered with assistance from Claude, according to Google’s advisory. Google identifies Ge as being with Anthropic.

The release also patches 53 High-severity vulnerabilities across a wide range of Chrome components, according to SecurityWeek’s count of Google’s advisory.

Advertisement

Google is restricting access to some vulnerability details until a majority of Chrome users have received the update, a practice designed to limit information that could help attackers target users who have not yet patched.

Chrome vulnerabilities have already been exploited this year

There is no indication so far that attackers are exploiting the four Critical vulnerabilities patched in Chrome 155. That distinction matters.

Chrome, however, has faced a steady stream of actively exploited vulnerabilities in 2026. In September, Google patched CVE-2026-85046 after confirming attackers were already exploiting the V8 vulnerability. It became the sixth Chrome zero-day known to have been exploited during the year.

Days later, another exploited Chrome vulnerability pushed that number to at least seven. Earlier attacks demonstrated how quickly browser vulnerabilities can become part of real-world campaigns.

One September campaign showed the potential consequences particularly clearly. Four espionage groups used the BlueMoon exploit kit to chain Chrome and Windows zero-days against organizations in the United States and Southeast Asia.

Chrome 155 also follows an unusually large security update just weeks earlier. Chrome 154 fixed 108 vulnerabilities, including 11 rated Critical.

The new release more than doubles that total with 247 security fixes, although vulnerability counts alone do not indicate how dangerous a browser release is. Severity, exploitability, exposure, and whether attackers are actively abusing a flaw are more important measures of immediate risk.

Security teams should verify Chrome 155 is actually installed

Chrome normally handles updates in the background, but users may need to relaunch the browser for a new version to take effect. In managed environments, administrators can also control how and when updates are deployed.

Google says Chrome 155 is rolling out as 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux.

Users can manually check their version by opening Chrome and navigating to Help > About Google Chrome. Chrome will check for available updates and prompt the user to relaunch when necessary.

For security administrators, the larger task is making sure updates have reached managed endpoints rather than assuming Chrome’s automatic updater has handled every device.

Advertisement

Organizations should:

  • Check Chrome versions across managed Windows, macOS, and Linux endpoints.
  • Identify devices still running older Chrome releases.
  • Make sure users relaunch Chrome when required to complete an update.
  • Review browser-update policies that may intentionally defer new versions.
  • Continue monitoring Google’s advisories as more technical information about the vulnerabilities becomes available.

That last step matters because Google is still withholding some technical details while Chrome 155 rolls out.

Browser patching has become an increasingly important part of endpoint security. The important question for organizations is not simply how many vulnerabilities Chrome contains, but how quickly they close the window between a fix becoming available and that fix reaching users.

For security teams managing Chrome fleets, 247 fixes make that window difficult to ignore.

Read next: See the four security habits worth adopting in 2026, including why faster software patching matters as attackers move quickly to exploit new vulnerabilities.

Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.