Google rolled out a sweeping security update to Chrome on October 6, 2026, sealing off 247 vulnerabilities across Windows, Mac, and Linux. Among these were four critical memory safety bugs, all rooted in use-after-free issues—scenarios where the browser references memory after it’s freed. The fixes land in version 155.0.8059.39 (and 155.0.8059.40 for Mac) for most platforms.
Key Critical Flaws & Who Found Them
The four high-risk bugs carry identifiers CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. CVE-2026-106382 impacts Chromecast and was reported internally on July 15, 2026. The Browser component bug (CVE-2026-106197) surfaced via external researcher Xinyang Ge on September 11, 2026. Two others, affecting Navigation and Track, were jointly discovered by Ge, Anthropic, and the AI tool Claude—on September 28 and 30 respectively. Though these flaws raise red flags for possible arbitrary code execution, Google has not confirmed that they enable sandbox escapes or functional exploit chains.
Wider Risks & Broader Patch Coverage
Apart from the critical use-after-free flaws, the update resolves numerous high severity issues in areas like graphics, media, browser interfaces, and security controls. One flaw in SiteIsolation tied to improper authorization, an integer overflow in WebGL, and several problems in ANGLE—including type confusion and uninitialized resources—also get addressed. V8, WebRTC, WebAudio, PDF, Fonts, Autofill, DevTools, Storage are among the many components cleaned up. The patches also sweep in medium- and low-severity fixes touching on information leaks, missing permissions, display errors, and memory handling.
Google credits its detection tools—such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL—for uncovering many of the bugs. The rollout is staged, meaning users may see the update at different times depending on platform and settings.
Importantly, the advisory makes clear that access to full bug details may remain restricted while Google ensures most users are patched. If a vulnerability involves a third-party library also used elsewhere, disclosure might be delayed until all affected projects are ready.
Security professionals and system administrators are advised to verify that their installations have moved to versions 155.0.8059.39 (or.40 on Mac) or higher, and review which components they deploy to ensure no affected service remains exposed. Close monitoring of exploit reports is also warranted, given the absence of confirmation that any of the flaws are currently being abused.
This Chrome update demonstrates again how crucial proactive patching is—when dozens of critical bugs emerge in one sweep, delayed updates become serious liabilities. Keeping browser versions current, enabling automated updates, and monitoring disclosures can make all the difference in preventing data loss or system compromise. For users, the takeaway is simple: if your Chrome isn’t already at or above 155.0.8059.39/.40, install the update immediately and keep an eye on the news in case any of these CVEs begin being exploited in the wild.