Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws.
All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.
The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher.
The fresh Chrome update resolves 53 high-severity vulnerabilities, including 34 reported by external researchers, Google notes in its advisory.
Approximately a dozen of these flaws were reported by Xinyang Ge. Many were found using AI, and Google will not reward the researcher for some of them.
The remaining 190 security defects are medium- and low-severity issues, most of which were discovered by Google.
External security researchers reported a total of 62 of the bugs patched in this Chrome update. Google paid roughly $33,000 in bug bounty rewards, but has yet to disclose the amounts handed out for almost 50 of the reports.
The most common types of vulnerabilities resolved include incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17), uninitialized resource (16), confused deputy (9), and improper input validation (9).
Google makes no mention of any of these vulnerabilities being exploited in the wild.
The latest Chrome iteration is now rolling out to users as versions 155.0.8059.39/.40 for Windows and macOS, and as version 155.0.8059.39 for Linux.
Related: Android’s October 2026 Updates Patch 25 Vulnerabilities
Related: Atlassian Patches Critical Vulnerability Affecting 8 Products
Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Related: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

