Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws
Key Takeaways Google has released a critical security update for Chrome across Windows, Mac, and Linux platforms. The update addresses a total of 247 vulnerabilities, including four critical...
Key Takeaways
- Google has released a critical security update for Chrome across Windows, Mac, and Linux platforms.
- The update addresses a total of 247 vulnerabilities, including four critical use-after-free flaws.
- The critical vulnerabilities affect components such as Chromecast, the Browser, Navigation, and Track.
- Users are urged to update their Chrome browsers immediately to patched versions 155.0.8059.39/.40 for Windows and Mac, and 155.0.8059.39 for Linux.
Major Chrome Update Patches 247 Vulnerabilities, Including Critical Code Execution Flaws
Google has deployed a significant security update for its Chrome browser, released on October 6, 2026. This comprehensive patch addresses a staggering 247 vulnerabilities across Windows, Mac, and Linux operating systems. Among these are four critical memory-safety flaws that could potentially lead to code execution.
Table Of Content
The updated Chrome versions are 155.0.8059.39 and 155.0.8059.40 for Windows and Mac users, and version 155.0.8059.39 for Linux users. While the critical bugs are identified as “use-after-free” vulnerabilities, Google’s official announcement does not detail specific exploitation vectors or confirm arbitrary code execution capabilities.
Critical Use-After-Free Vulnerabilities Identified
The four critical vulnerabilities are all categorized as use-after-free issues, a class of memory corruption bugs where an application attempts to access memory after it has been deallocated. This can lead to crashes, arbitrary code execution, or other unpredictable behavior.
- CVE-2026-106382: This vulnerability affects Chromecast and was reported by Google on July 15, 2026.
- CVE-2026-106197: Impacting the Browser component, this flaw was discovered and reported by security researcher Xinyang Ge on September 11, 2026.
- CVE-2026-106358: Affecting the Navigation component, this issue was reported on September 28, 2026.
- CVE-2026-106347: This vulnerability is present in the Track component and was reported on September 30, 2026.
Notably, Xinyang Ge of Anthropic, with assistance from the AI model Claude, is credited with discovering both CVE-2026-106358 and CVE-2026-106347, highlighting the growing role of artificial intelligence in modern vulnerability research.
The advisory from Google does not specify whether these particular flaws allow for sandbox escapes, require user interaction, or can be chained together to form a complete attack.
Broader Scope of Fixes
Beyond the critical issues, the update also resolves numerous high-severity vulnerabilities spanning various components including graphics, media interfaces, browser functionalities, and security controls. For instance, CVE-2026-102322 addresses an incorrect authorization flaw in SiteIsolation, while CVE-2026-106239 corrects an integer overflow within WebGL. Several vulnerabilities in ANGLE relate to uninitialized resources, alongside other type confusion and use-after-free bugs.
The V8 JavaScript engine also received fixes for race conditions, type confusion, and use-after-free bugs. Other components benefiting from this update include WebRTC, WebAudio, PDF, Storage, Autofill, Fonts, and DevTools. The update also tackles medium- and low-severity issues, which encompass information leaks, missing authorization checks, misleading user interfaces, and various resource-handling weaknesses.
Google says that many of these security flaws were identified through advanced internal testing tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, underscoring the company’s robust security testing methodologies.
While Google has not confirmed active exploitation of these vulnerabilities in the wild, the absence of such a statement does not preclude prior exploitation. Google typically restricts access to detailed bug information until a majority of users have updated, or if a vulnerability affects a third-party library that has not yet been patched in other projects.
What You Should Do
- Update Immediately: Ensure your Chrome browser is updated to version 155.0.8059.39/.40 (Windows/Mac) or 155.0.8059.39 (Linux). Chrome typically updates automatically, but users should manually check for updates via “Settings > About Chrome” to expedite the process.
- Verify Version: Confirm your browser is running the patched version to ensure protection against these vulnerabilities.
- Stay Informed: Keep an eye on official Google Chrome release channels for further security advisories.
- Educate Users: For organizations, communicate the importance of this update to all users and provide clear instructions for updating their browsers.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.