CVE-2026-106382
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Vulnerabilities · 8h ago
Google rolled out Chrome 155 to fix 247 vulnerabilities, including four critical use-after-free bugs in the browser, navigation, Chromecast, and Track components. The update is moving out as versions 155.0.8059.39/.40 on Windows and macOS, and 155.0.8059.39 on Linux.
Use-after-free bugs happen when Chrome keeps using memory after it has been freed, which can let a crafted page make the browser misbehave or run attacker-controlled code outside the sandbox. Google says one flaw was found by its own team and three were reported by Xinyang Ge, with some of those discoveries made using AI.
For teams that manage Chrome fleets, this is a routine patch cycle with a large fix count and no wild-exploitation signal. The open question is less about incident response than about how AI-assisted findings and bounty decisions will shape future reporting pressure.
CVSS 9.6 CRITICAL: use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 9.6 CRITICAL: use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVSS 8.8 HIGH: use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
2 sources covering this story
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
CVE-2026-106269: Google Chrome
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
CVE-2026-106234: Google Chrome
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension.
CVE-2026-106355: Google Chrome
Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page.
CVE-2026-106272: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic.
CVE-2026-106345: Google Chrome
Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page.
CVE-2026-106310: Google Chrome
Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page.
CVE-2026-106251: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic.
CVE-2026-106236: Google Chrome
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic.
CVE-2026-106334: Google Chrome
Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page.
CVE-2026-106294: Google Chrome
Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic.
CVE-2026-106390: Google Chrome
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page.
Part of the PlainSec briefing for 2026-10-07