GOOGLE has released Chrome 155, addressing a total of 247 vulnerabilities across desktop and Linux builds. Four of these are critical-use-after-free flaws affecting Chrome’s Chromecast, Browser, Navigation, and Track components. The tracked CVEs are CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. The first bug was discovered by Google itself, while the other three were reported by Xinyang Ge, who used AI to help identify two of the defects. Google has not disclosed bug-bounty amounts for all reports.
In addition to the four critical issues, the update patches 53 high-severity vulnerabilities (34 of which were reported by external researchers), with several of those also linked to AI-guided discoveries. Google notes that about a dozen of the high-severity flaws were reported by Xinyang Ge, and that many were found using AI; the company has not indicated rewards for some of these reports. The majority of the remaining 190 defects are medium- and low-severity issues, largely uncovered by Google itself.
External researchers contributed 62 of the patched bugs, and Google has paid roughly $33,000 in bug-bounty rewards so far, though amounts for nearly 50 reports remain undisclosed. The updated Chrome versions are 155.0.8059.39/40 for Windows and macOS, and 155.0.8059.39 for Linux. No exploitation in the wild was disclosed.