CVE-2026-106382
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Vulnerabilities & Exploits
Google rolled out Chrome 155 to fix 247 vulnerabilities, including four critical use-after-free bugs in the browser, navigation, Chromecast, and Track components. The update is moving out as versions 155.0.8059.39/.40 on Windows and macOS, and 155.0.8059.39 on Linux.
Use-after-free bugs happen when Chrome keeps using memory after it has been freed, which can let a crafted page make the browser misbehave or run attacker-controlled code outside the sandbox. Google says one flaw was found by its own team and three were reported by Xinyang Ge, with some of those discoveries made using AI.
For teams that manage Chrome fleets, this is a routine patch cycle with a large fix count and no wild-exploitation signal. The open question is less about incident response than about how AI-assisted findings and bounty decisions will shape future reporting pressure.
2 sources · 9h ago
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 8.8 HIGH: use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
SecurityWeek
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
originalCVE Program records
CVE-2026-106269: Google Chrome
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
originalCVE Program records
CVE-2026-106234: Google Chrome
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension.
originalPart of the PlainSec briefing for 2026-10-07
Every edition of this story: Chrome 155 Patches Four Critical Memory Bugs