Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws.
All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.
The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher.
The fresh Chrome update resolves 53 high-severity vulnerabilities, including 34 reported by external researchers, Google notes in its advisory.
Approximately a dozen of these flaws were reported by Xinyang Ge. Many were found using AI, and Google will not reward the researcher for some of them.
The remaining 190 security defects are medium- and low-severity issues, most of which were discovered by Google.
External security researchers reported a total of 62 of the bugs patched in this Chrome update. Google paid roughly $33,000 in bug bounty rewards, but has yet to disclose the amounts handed out for almost 50 of the reports.
The most common types of vulnerabilities resolved include incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17), uninitialized resource (16), confused deputy (9), and improper input validation (9).
Google makes no mention of any of these vulnerabilities being exploited in the wild.
The latest Chrome iteration is now rolling out to users as versions 155.0.8059.39/.40 for Windows and macOS, and as version 155.0.8059.39 for Linux.