Software

Google Ships Chrome 155 With 247 Fixes Including Four Critical Flaws

Chrome 155 arrives with 247 security fixes, four critical use-after-free bugs, and credits for Anthropic's Claude-assisted researcher and OpenAI's Codex Security team.

T
By TechQuire Daily Staff TechQuire Daily Staff
October 7, 2026 / 7 min read

Google released Chrome 155 to the Stable channel on October 6, 2026, delivering 247 security fixes for desktop users on Windows, Mac and Linux. The update is version 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux, and it includes four vulnerabilities rated Critical. The total is far above the volume of recent Chrome security releases. The update is rolling out over the coming days and weeks.

Chrome 155 also reached Android as 155.0.8059.39 and iOS as 155.0.8059.37. The desktop release followed an early stable version, 155.0.8059.26/.27, which went to a small percentage of Windows and Mac users on September 30 before the wider October 6 rollout. For comparison, the prior October 1 desktop update to 154.0.8037.97 contained 11 fixes, and Chrome 154.0.8037.92 shipped with 32 fixes on September 29. The jump to 247 fixes is therefore not routine maintenance but a substantial security response.

All four critical flaws are use-after-free bugs, a memory safety error that can lead to arbitrary code execution. Google reported CVE-2026-106382 in Chromecast internally. Xinyang Ge reported CVE-2026-106197 in the Browser component. Xinyang Ge of Anthropic, assisted by Claude, reported CVE-2026-106358 in Navigation and CVE-2026-106347 in Track. OpenAI's Codex Security team also contributed two high-severity findings. Google restricts access to bug details and links until a majority of users are updated with a fix.

Key Facts

gHacks reported on October 7 that Google released Chrome 155 to the Stable channel on October 6, 2026 with 247 security fixes, according to the Chrome Releases blog. Four of the 247 fixes are rated Critical, 53 are High, 122 are Medium and 68 are Low. The count is far above the prior October 1 desktop update to 154.0.8037.97, which contained 11 fixes, and Chrome 154.0.8037.92, which shipped with 32 fixes on September 29. Chrome 155 is also out on Android as 155.0.8059.39 and on iOS as 155.0.8059.37.

PiunikaWeb reported on October 7 that the two critical bugs credited to Anthropic researcher Xinyang Ge, directly assisted by Claude, are CVE-2026-106358 in Navigation and CVE-2026-106347 in Track, both use-after-free bugs that can open the door to running malicious code. Xinyang Ge and Claude also submitted ten more high-severity bugs across the PDF engine, WebRTC and media components, including CVE-2026-106278, CVE-2026-106233, CVE-2026-106318, CVE-2026-106411, CVE-2026-106423, CVE-2026-106357, CVE-2026-106383, CVE-2026-106349, CVE-2026-106421 and CVE-2026-106204. OpenAI's Codex Security team reported two high-severity flaws, including a use-after-free issue in HTML (CVE-2026-106257) and a type confusion bug in the V8 engine (CVE-2026-106240).

CybersecurityNews reported on October 7 that Google identifies the four critical bugs as use-after-free issues but does not describe exploitation methods or confirm arbitrary code execution. The report dates for the four critical flaws vary: CVE-2026-106382 affects Chromecast and was reported by Google on July 15, 2026; CVE-2026-106197 affects the Browser component and was reported by Xinyang Ge on September 11, 2026; CVE-2026-106358 affects Navigation and was reported on September 28, 2026; and CVE-2026-106347 affects Track and was reported on September 30, 2026. Google credits Xinyang Ge of Anthropic, assisted by Claude, for both the Navigation and Track bugs.

Malwarebytes reported on October 7 that Chrome and ChromeOS received updates fixing 247 vulnerabilities, with three likely high-impact flaws highlighted. CVE-2026-106197 is a critical use-after-free in the Browser module; exploitation could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. CVE-2026-106358 is another critical use-after-free in Navigation, a component central to ordinary browsing. Among the high-severity entries, Google lists a $5,000 bounty for incorrect authorization in Site Isolation (CVE-2026-102322). Google says many bugs were detected with AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer or AFL, and has not confirmed in-the-wild exploitation.

Analysis

The headline number, 247 security fixes in a single stable release, is extraordinary for Chrome and signals a concentrated push rather than business as usual. The prior two desktop updates in late September and early October carried 32 and 11 fixes respectively. A jump of this magnitude suggests either a backlog of reported issues being cleared at once, a surge in research activity, or both. The severity distribution, with four Critical and 53 High, is also notable because these are the categories that matter most for real-world risk.

What this really means is that AI-assisted vulnerability research has crossed a threshold from experiment to operational practice. Two critical, remotely exploitable memory safety bugs in core browser components were found by a human researcher working directly with Claude, an AI model from Anthropic. Those bugs, CVE-2026-106358 in Navigation and CVE-2026-106347 in Track, are use-after-free flaws that can open the door to running malicious code. Navigation is especially concerning because it is central to ordinary browsing, meaning a broad set of users could be exposed if an exploit existed. The fact that a single researcher, aided by an AI assistant, contributed both critical bugs plus ten high-severity findings across the PDF engine, WebRTC and media components is a strong signal about how security research is changing.

The bigger picture here is that Chrome's security model depends heavily on third-party researchers and now increasingly on AI tools. Google's bug bounty and credit system has long incentivized external discovery, but the involvement of Anthropic's Claude and OpenAI's Codex Security team in the same update points to a new competitive dynamic. OpenAI's team reported two high-severity flaws, a use-after-free in HTML and a type confusion in V8, showing that multiple AI organizations are now actively probing browser code. This could accelerate the pace of vulnerability discovery, which is good for defenders if patches arrive quickly, but it also raises the question of whether attackers will use similar tools to find flaws before they are fixed.

The four critical bugs are all use-after-free issues, a memory safety category that remains stubbornly common in large codebases like Chrome. Google's release notes restrict access to bug details and links until a majority of users are updated with a fix, and keep restrictions in place longer when a bug sits in a third-party library other projects also depend on. This is a sensible policy to prevent attackers from reverse-engineering exploits, but it also means the public cannot yet gauge how dangerous each flaw truly is. Google did not say whether any of the 247 flaws have been exploited in the wild, leaving a critical unknown for defenders.

Why It Matters

For ordinary users, the practical takeaway is straightforward: Chrome 155 should be installed as soon as possible. The update includes four critical use-after-free bugs, and at least one, CVE-2026-106197 in the Browser module, could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, according to Malwarebytes. That is the kind of flaw that turns a visit to a malicious or compromised website into direct code execution on the underlying operating system. Browsers are among the most exposed pieces of software on any device, so a large batch of memory safety fixes is not something to defer.

The scale of this update also matters for the broader security ecosystem. Chrome's release cycle is closely watched because the browser holds a vast share of the desktop and mobile market. When Google ships 247 fixes at once, it sets a benchmark for how quickly other vendors may need to respond to similar research pressure. The involvement of AI assistants in finding critical bugs could encourage more researchers to adopt such tools, potentially increasing the number of reports that vendors must triage. That could lead to more frequent large updates like Chrome 155, or it could push vendors to improve automated triage and patching pipelines.

Another reason this matters is the light it shines on the maturity of AI-assisted security work. Claude and the Codex Security team are not being credited with minor issues; they are associated with critical and high-severity flaws in core components. That lends credibility to the idea that AI can meaningfully augment human expertise in vulnerability discovery. At the same time, the restricted disclosure of details means the public cannot independently verify the full impact. The security community will be watching closely for follow-up analysis, exploit proofs, and any signs of in-the-wild activity.

Next Up

Google will continue rolling out Chrome 155 across desktop, Android and iOS over the coming days and weeks. Users can manually update via the About Google Chrome menu and relaunch the browser. ChromeOS updates install automatically once the device is connected and require a restart. Google has not indicated when it will lift restrictions on bug details, but its standard practice is to wait until a majority of users have updated. The company may also publish additional information if any of the flaws turn out to be exploited in the wild.

The bigger question is whether this release marks a lasting shift toward AI-assisted vulnerability research or a one-time spike. If Anthropic's Claude and OpenAI's Codex Security team continue to produce critical findings, competitors and security vendors may accelerate their own AI research efforts. That could lead to more frequent disclosures, larger patch batches, and a faster overall tempo in browser security. For now, Chrome 155 stands as a record-setting update with 247 fixes, four critical bugs, and a clear signal that AI is now part of the vulnerability discovery pipeline.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.