GOOGLE has pushed Chrome 155 to the Stable channel, delivering a substantial security update that fixes 247 flaws, including four critical use-after-free (UAF) bugs. The release addresses a total of six CVEs, with the four critical UAFs ranked at the top of the severity scale. The highest CVSSv3 score among the flaws is 9.6. Notably, Google has not reported any of the fixed issues as being exploited in the wild to date.
The notable CVEs listed include CVE-2026-106382, CVE-2026-106197, CVE-2026-106358 and CVE-2026-106347, all described as use-after-free in different Chrome components such as Chromecast, Browser, Navigation and Track.
Affected versions and rollout details indicate that all Chrome builds prior to 155 are affected. The fixed versions are Windows and macOS: 155.0.8059.39/40, and Linux: 155.0.8059.39. Google notes that the rollout will occur over the coming days or weeks, with other Chromium-based browsers likely requiring their own patches. The update targets memory safety in code handling web content, a broad risk given Chrome’s billions of users. Affected product areas include ANGLE, WebRTC, Media, PDF and Autofill.
Evidence in the article also points to ongoing attribution of several bugs to AI-assisted research. Administrators are urged to apply the patch promptly via Chrome’s About page and to coordinate updates across enterprise management tools and rival browsers where suitable.