Google has released Chrome 155 with fixes for 247 security vulnerabilities, including four rated critical, in one of the largest Chrome security updates on record by count. The release came out on October 7.
The update covers Windows, macOS and Linux, with builds 155.0.8059.39 and 155.0.8059.40. Google reports no exploitation of the flaws in the wild.
The Four Critical Use-After-Free Flaws
All four critical vulnerabilities are use-after-free bugs, a memory-safety class in which code keeps using memory after it has been freed. They are:
- CVE-2026-106382, in Chromecast.
- CVE-2026-106197, in the Browser component.
- CVE-2026-106358, in Navigation.
- CVE-2026-106347, in Track.
How the 247 Fixes Break Down
Of the 247 flaws, 4 are critical, 53 are high severity and 190 are medium or low. External researchers reported 62 of the bugs.
Researchers, AI-Assisted Discoveries and Bounties
About a dozen of the high-severity bugs came from researcher Xinyang Ge, and many of those were found with the help of AI, according to the release information. Google declined to pay rewards for some of the bugs found with AI.
Google disclosed about $33,000 in bounties across the release. Amounts for nearly 50 reports were not disclosed, so the total paid is higher than the published figure.
The Most Common Weakness Classes
The most frequent bug classes in the release were incorrect authorization, which accounted for 41 flaws; use-after-free, which accounted for 34; and missing authorization, which also accounted for 34. Authorization problems together make up a large share of the fixes, standing out against the memory-safety bugs that usually dominate browser patch notes.
Exploitation Status and How to Update
Google says it has seen no in-the-wild exploitation of any of the 247 vulnerabilities. That differs from releases that fix a flaw already used in attacks, and it means the update is a routine, if very large, fix cycle rather than an emergency response.
Updating to Chrome 155
The response is to update to Chrome 155. Chrome typically downloads updates automatically, and users can confirm the installed version from the browser’s About page. The fixed builds on Windows, macOS and Linux are 155.0.8059.39 and 155.0.8059.40.
The Chrome 155 build numbers, 155.0.8059.39 and 155.0.8059.40, apply across the three desktop platforms. The 62 externally reported bugs account for a minority of the 247 fixes. Google’s bounty disclosure of about $33,000 covers only the reports for which amounts were stated, and nearly 50 reports carry no disclosed amount.
A Record-Scale Release
The count of 247 places this among the biggest single Chrome security releases. The breakdown shows that most of the fixes are not in the highest severity tier: 190 of the 247 are medium or low, and 53 more are high.
The role of AI in finding bugs is a notable thread in this release. Xinyang Ge’s contribution of about a dozen high-severity bugs, many discovered with AI assistance, along with Google’s decision to decline rewards for some AI-found bugs, suggests Google handles that category of reports differently from traditional submissions. The release information does not explain the criteria Google applied.
Among the critical bugs, the component names show the range of code involved: Chromecast, the Browser process, Navigation and Track. Each was found to be a use-after-free, and each carries the critical rating. The high-severity group of 53 flaws is the largest category above the medium and low tier, which holds 190 of the fixes.
Browser vulnerabilities matter because Chrome is installed on a very large number of devices, and a critical use-after-free flaw in a component such as Navigation or Browser is the kind of bug attackers look to chain into a full exploit. With four such flaws fixed in this release, the window between release and installation is the period in which unpatched browsers remain exposed.
