Skip to content
feed: live
0dayNews
browser

Chrome 155 Patches 4 Critical UAF Bugs, 247 Total

Google shipped Chrome 155 with 247 fixes, including four critical use-after-free bugs in core browser components. No active exploitation reported yet.

Chrome 155 Patches 4 Critical UAF Bugs, 247 Total
Image: 0dayNews / 0dayNews Editorial · All rights reserved
fuseMarisol "Fuse" Delgado·Published ·1 min read

Google pushed Chrome 155 (versions 155.0.8059.39 and .40 on Windows and macOS, 155.0.8059.39 on Linux) with 247 security fixes, four of them critical.

The four critical bugs

All four are use-after-free vulnerabilities in different browser components. UAF bugs in browser infrastructure are worth taking seriously: an attacker who can control freed memory can often execute code inside the renderer sandbox via a crafted page.

  • CVE-2026-106382 in Chromecast, CVSS 9.6. Found internally by Google.
  • CVE-2026-106197 in Browser, CVSS 9.6. Reported by Xinyang Ge.
  • CVE-2026-106358 in Navigation, CVSS 9.6. Reported by Xinyang Ge.
  • CVE-2026-106347 in Track, CVSS 8.8. Reported by Xinyang Ge. Chromium’s internal severity label is “critical,” but NVD rates this one high, not critical.

Beyond those four: 53 high-severity bugs (34 from external researchers) and 190 medium and low findings round out the patch set.

Update now, especially on managed fleets

Consumer Chrome updates automatically. To confirm the version: three-dot menu > Help > About Google Chrome. You want 155.0.8059.39 or .40.

Enterprise teams running managed installs with deferred update policies should treat this as a priority push. Three of these four bugs are CVSS 9.6, in Browser, Navigation, and Chromecast, and all were reported by external researchers. External discovery means more than one person now knows the triggering conditions. Waiting a few extra weeks on this one is the wrong call.

Google has not reported active exploitation for any of these bugs as of the release date. That changes faster than patch windows allow for.

Bug bounty notes

Xinyang Ge identified several of the high-severity findings using AI-assisted research techniques. Google disclosed approximately $33,000 in bounties for this release, with another roughly 50 reports still in payout review.


Chrome has shipped patches for exploited zero-days multiple times this year: seven exploited zero-days through September, including a V8 engine zero-day and a pairing with Windows flaws in the BlueMoon exploit kit. This release has no confirmed active exploitation, but Chrome UAF bugs have a consistent history of being picked up quickly.

Google also released its October Android security bulletin today, covering 25 vulnerabilities including a critical privilege escalation.

Source: SecurityWeek

Related CVEs
  • [ CRITICAL ]CVE-2026-106382Use-after-free in Chromecast allows sandbox code execution
  • [ CRITICAL ]CVE-2026-106197Use-after-free in Chrome Browser component enables sandbox RCE
  • [ CRITICAL ]CVE-2026-106358Use-after-free in Chrome Navigation allows sandbox code execution
  • [ HIGH ]CVE-2026-106347Use-after-free in Chrome Track component allows sandbox code execution

Found this useful? Share it.