Google Chrome Update Fixes 247 Vulnerabilities, Including Four Critical Memory Safety Flaws
Google Chrome version 155.0.8059.39/.40 addresses 247 vulnerabilities, including four critical use-after-free flaws.

Google has released a significant security update for its Chrome browser, patching a staggering 247 vulnerabilities across Windows, Mac, and Linux platforms. The update, which brings the browser to versions 155.0.8059.39/.40 for Windows and Mac, and 155.0.8059.39 for Linux, addresses a wide range of security weaknesses, including four critical memory-safety flaws.
At the forefront of the fixes are four critical use-after-free vulnerabilities. These types of bugs occur when software attempts to access memory that has already been deallocated, potentially leading to crashes or, more concerningly, arbitrary code execution. While Google has not confirmed any in-the-wild exploitation of these specific flaws, their critical severity warrants immediate attention from users and administrators.
The four critical vulnerabilities are identified as CVE-2026-106382 (affecting Chromecast), CVE-2026-106197 (affecting the Browser component), CVE-2026-106358 (affecting Navigation), and CVE-2026-106347 (affecting Track). Notably, CVE-2026-106358 and CVE-2026-106347 were reported by Xinyang Ge of Anthropic, with assistance from Claude, highlighting the growing role of AI in vulnerability research.
Beyond the critical use-after-free bugs, the update also tackles numerous high-severity issues across various Chrome components. These include flaws in SiteIsolation, ANGLE (a graphics engine), and the V8 JavaScript engine. Specific high-severity vulnerabilities mentioned involve incorrect authorization in SiteIsolation (CVE-2026-102322) and an integer overflow in WebGL (CVE-2026-106239).
The V8 engine, a core component responsible for executing JavaScript, received fixes for several issues, including race conditions, type confusion, and additional use-after-free vulnerabilities. The ANGLE component also saw patches for vulnerabilities related to uninitialized resources, type confusion, and use-after-free bugs.
Other components that received security attention include WebRTC, WebAudio, PDF handling, Storage, Autofill, Fonts, and DevTools. The remaining vulnerabilities patched range in severity from medium to low, encompassing issues such as information leaks, missing authorization checks, misleading interface elements, and other resource-handling weaknesses.
Google employs a suite of advanced security testing tools, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, to detect many of these vulnerabilities. The company typically restricts the release of detailed bug information until a majority of users have applied the patches, a common practice to prevent exploitation by malicious actors.
This extensive patch release underscores the ongoing challenges in securing complex software like web browsers. Users are strongly advised to ensure their Google Chrome installations are updated to the latest versions to protect themselves from potential exploitation of these newly fixed vulnerabilities.
This update to Chrome 155 addresses a significantly larger number of vulnerabilities than previously reported, totaling 247. While the initial disclosure focused on four critical use-after-free flaws, this article details the breakdown of all patched issues, including 53 high-severity vulnerabilities and 190 medium- and low-severity ones. It also highlights that external researchers reported 62 of the total bugs, with Google paying out approximately $33,000 in bug bounties, though many reports remain unrewarded.
This update for Chrome and ChromeOS addresses a significant number of vulnerabilities, bringing the total to 247 security fixes. Among these, four are rated critical, including two use-after-free flaws in the Browser and Navigation modules (CVE-2026-106197 and CVE-2026-106358) that could allow remote code execution outside the sandbox. Additionally, a high-severity type confusion vulnerability in the V8 JavaScript engine (CVE-2026-106240) has also been patched.