Tech News

Chrome 155 Patches 247 Security Flaws, Including 4 Critical Ones

Chrome 155, rolled out by Google since October 6, 2026, fixes 247 security flaws. Among them, four vulnerabilities are critical, and several were discovered with the help of AI. Here’s what you need to know.

On October 6, 2026, Google published a new bulletin on the Chrome blog to announce the release of Chrome 155 (stable channel). And this is a major security update, as Google lists 247 fixes for vulnerabilities: 4 critical, 53 high severity, 122 medium severity, and 68 low severity. For comparison, the minor Chrome 154 update released on October 1 (version 154.0.8037.97/.98) included 11, and Chrome 154 itself, released on September 22, fixed 108.

As a reminder, Google switched to a two-week release cycle starting with Chrome 153 on September 8. This means a new stable version of Chrome every 2 weeks instead of every 4 weeks.

Four critical flaws, including two found with Claude

The four critical flaws are all use-after-free vulnerabilities, meaning they involve the use of memory that has already been freed. This type of bug can lead to memory corruption and, in the worst case, arbitrary code execution. They are assigned the following CVE identifiers:

  • CVE-2026-106382 : flaw in the Chromecast component, discovered internally by Google.
  • CVE-2026-106197 : flaw in the Browser component, reported by Xinyang Ge.
  • CVE-2026-106358 : flaw in the Navigation component, reported by Xinyang Ge (Anthropic), with assistance from Claude.
  • CVE-2026-106347 : flaw in the Track component, reported by Xinyang Ge (Anthropic), with assistance from Claude.

Looking through the bulletin, you can find the mention “assisted by Claude” on 12 vulnerabilities in total: the 2 critical flaws mentioned above and 10 high-severity flaws, in components such as V8, PDF, WebRTC, and Media. OpenAI’s tool also appears: Codex Security is credited with two high-severity flaws, in V8 and HTML. And then, there are all the flaws directly attributed to Google, where AI was probably involved given the sheer number of issues.

The bulletin does not mention any active exploitation, and technical details are not available. "Access to bug details and links may remain restricted until a majority of users have received the fix," Google explains.

How can you protect yourself from these flaws?

Chrome updates automatically, but fixes only take effect after restarting the browser. To force a check, open the main menu (the three dots in the top-right corner), then click Help, then About Google Chrome. Once the update has downloaded, click Relaunch.

The versions to install are as follows:

  • Windows and macOS : Chrome 155.0.8059.39/.40 or later.
  • Linux : Chrome 155.0.8059.39 or later.
  • Android : Chrome 155.0.8059.39 or later.

As usual, the rollout is gradual and will take place over several days, or even several weeks.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.