Vulnerabilities & Exploits

Chrome 155 Patches Four Critical Memory Bugs

Google rolled out Chrome 155 to fix 247 vulnerabilities, including four critical use-after-free bugs in the browser, navigation, Chromecast, and Track components. The update is moving out as versions 155.0.8059.39/.40 on Windows and macOS, and 155.0.8059.39 on Linux.

Use-after-free bugs happen when Chrome keeps using memory after it has been freed, which can let a crafted page make the browser misbehave or run attacker-controlled code outside the sandbox. Google says one flaw was found by its own team and three were reported by Xinyang Ge, with some of those discoveries made using AI.

For teams that manage Chrome fleets, this is a routine patch cycle with a large fix count and no wild-exploitation signal. The open question is less about incident response than about how AI-assisted findings and bounty decisions will shape future reporting pressure.

2 sources · 9h ago

CVE-2026-106382

NVD KEV

CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

CVE-2026-106197

NVD KEV

CVSS 9.6 CRITICAL: use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

CVE-2026-106358

NVD KEV

CVSS 9.6 CRITICAL: use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

CVE-2026-106347

NVD KEV

CVSS 8.8 HIGH: use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

Timeline

Sources

Part of the PlainSec briefing for 2026-10-07

Every edition of this story: Chrome 155 Patches Four Critical Memory Bugs

More from today