Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex
October 7, 2026
Critical OpenSSH Flaws Allow Plaintext Recovery, File Write, and Injection
October 7, 2026
Critical WordPress Flaws Allow XSS, SQL Injection, Data Disclosure
October 7, 2026
Home/CyberSecurity News/Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws
CyberSecurity News

Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws

Key Takeaways Google has released a critical security update for Chrome across Windows, Mac, and Linux platforms. The update addresses a total of 247 vulnerabilities, including four critical...

Jennifer sherman
Jennifer sherman
October 7, 2026 3 Min Read
2 0

Key Takeaways

  • Google has released a critical security update for Chrome across Windows, Mac, and Linux platforms.
  • The update addresses a total of 247 vulnerabilities, including four critical use-after-free flaws.
  • The critical vulnerabilities affect components such as Chromecast, the Browser, Navigation, and Track.
  • Users are urged to update their Chrome browsers immediately to patched versions 155.0.8059.39/.40 for Windows and Mac, and 155.0.8059.39 for Linux.

Major Chrome Update Patches 247 Vulnerabilities, Including Critical Code Execution Flaws

Google has deployed a significant security update for its Chrome browser, released on October 6, 2026. This comprehensive patch addresses a staggering 247 vulnerabilities across Windows, Mac, and Linux operating systems. Among these are four critical memory-safety flaws that could potentially lead to code execution.

Table Of Content

  • Key Takeaways
  • Major Chrome Update Patches 247 Vulnerabilities, Including Critical Code Execution Flaws
  • Critical Use-After-Free Vulnerabilities Identified
  • Broader Scope of Fixes
  • What You Should Do

The updated Chrome versions are 155.0.8059.39 and 155.0.8059.40 for Windows and Mac users, and version 155.0.8059.39 for Linux users. While the critical bugs are identified as “use-after-free” vulnerabilities, Google’s official announcement does not detail specific exploitation vectors or confirm arbitrary code execution capabilities.

Critical Use-After-Free Vulnerabilities Identified

The four critical vulnerabilities are all categorized as use-after-free issues, a class of memory corruption bugs where an application attempts to access memory after it has been deallocated. This can lead to crashes, arbitrary code execution, or other unpredictable behavior.

  • CVE-2026-106382: This vulnerability affects Chromecast and was reported by Google on July 15, 2026.
  • CVE-2026-106197: Impacting the Browser component, this flaw was discovered and reported by security researcher Xinyang Ge on September 11, 2026.
  • CVE-2026-106358: Affecting the Navigation component, this issue was reported on September 28, 2026.
  • CVE-2026-106347: This vulnerability is present in the Track component and was reported on September 30, 2026.

Notably, Xinyang Ge of Anthropic, with assistance from the AI model Claude, is credited with discovering both CVE-2026-106358 and CVE-2026-106347, highlighting the growing role of artificial intelligence in modern vulnerability research.

The advisory from Google does not specify whether these particular flaws allow for sandbox escapes, require user interaction, or can be chained together to form a complete attack.

Broader Scope of Fixes

Beyond the critical issues, the update also resolves numerous high-severity vulnerabilities spanning various components including graphics, media interfaces, browser functionalities, and security controls. For instance, CVE-2026-102322 addresses an incorrect authorization flaw in SiteIsolation, while CVE-2026-106239 corrects an integer overflow within WebGL. Several vulnerabilities in ANGLE relate to uninitialized resources, alongside other type confusion and use-after-free bugs.

The V8 JavaScript engine also received fixes for race conditions, type confusion, and use-after-free bugs. Other components benefiting from this update include WebRTC, WebAudio, PDF, Storage, Autofill, Fonts, and DevTools. The update also tackles medium- and low-severity issues, which encompass information leaks, missing authorization checks, misleading user interfaces, and various resource-handling weaknesses.

Google says that many of these security flaws were identified through advanced internal testing tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, underscoring the company’s robust security testing methodologies.

While Google has not confirmed active exploitation of these vulnerabilities in the wild, the absence of such a statement does not preclude prior exploitation. Google typically restricts access to detailed bug information until a majority of users have updated, or if a vulnerability affects a third-party library that has not yet been patched in other projects.

What You Should Do

  • Update Immediately: Ensure your Chrome browser is updated to version 155.0.8059.39/.40 (Windows/Mac) or 155.0.8059.39 (Linux). Chrome typically updates automatically, but users should manually check for updates via “Settings > About Chrome” to expedite the process.
  • Verify Version: Confirm your browser is running the patched version to ensure protection against these vulnerabilities.
  • Stay Informed: Keep an eye on official Google Chrome release channels for further security advisories.
  • Educate Users: For organizations, communicate the importance of this update to all users and provide clear instructions for updating their browsers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor

Next Post

The Best IAST Tools of 2024: Ranked and Reviewed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws
October 7, 2026
Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor
October 7, 2026
Top 10 Best DAST Tools in 2026 [Ranked & Scored]
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us