Chrome 155 reaches the Stable channel with 247 security fixes, including four Critical use-after-free bugs (CVE-2026-106382, 106197, 106358, 106347); update to 155.0.8059.39 or later
Google moved Chrome 155 to the Stable channel on 6 October 2026, version 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux, rolling out over the following days and weeks. The release fixes 247 security bugs. Google rates four as Critical, all use-after-free memory errors: CVE-2026-106382 in Chromecast (found by Google), CVE-2026-106197 in the browser process, and CVE-2026-106358 in Navigation and CVE-2026-106347 in Track, the last two reported by Xinyang Ge of Anthropic with help from Claude. Another 53 are rated High, among them several uninitialised-resource and type-confusion bugs in the ANGLE graphics layer, a SiteIsolation authorization flaw (CVE-2026-102322), and race conditions in Fonts; the rest are Medium and Low. Google's release note does not say any of them are being exploited, and it keeps bug details restricted until most users have updated. Google does not publish CVSS scores for Chrome bugs. Browsers built on Chromium, such as Microsoft Edge, Brave and Opera, will need their own updates. Primary: Chrome Releases blog.
- Product
- Google Chrome desktop (Windows, Mac, Linux); Chromium-based browsers
- Versions
- Chrome before 155.0.8059.39 (fixed 155.0.8059.39/.40)
- CVSS
- Not published by Google; Chrome severity Critical for 4 bugs, High for 53
- Exploited in Australia?
- unknown
- Patch to
- Update Chrome to 155.0.8059.39 or later and relaunch the browser (managed fleets: push the update through your management tool and enforce a relaunch deadline). Watch for matching Chromium-based browser updates such as Microsoft Edge.
Primary: Google Chrome Releases — Stable Channel Update for Desktop (6 Oct 2026, Chrome 155.0.8059.39) · Vendor: CVE record — CVE-2026-106382 (Chrome, published 6 Oct 2026) · CVE: CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347, CVE-2026-102322
