# Chrome 155 Update Patches 247 Vulnerabilities Including 4 Critical Use-After-Free Flaws (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347)

> Google released Chrome 155 (155.0.8059.39/.40 for Windows/macOS, 155.0.8059.39 for Linux) fixing 247 security issues: 4 Critical, 53 High, 122 Medium and 68 Low. The four Critical flaws are use-after-free bugs in Chromecast, Browser, Navigation and Track; Google does not report exploitation in the wild.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T12:56:51.030Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3251
- **ID:** TL-2026-3251
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347, CVE-2026-106240, CVE-2026-106257, CVE-2026-102322, CVE-2026-106239, CVE-2026-106278, CVE-2026-106233, CVE-2026-106318, CVE-2026-106411, CVE-2026-106423, CVE-2026-106357, CVE-2026-106383, CVE-2026-106349, CVE-2026-106421, CVE-2026-106204

## Description

On 2026-10-06/07 Google promoted Chrome 155 to the Stable channel with 247 security fixes, far above recent cadence (the 2026-10-01 desktop update 154.0.8037.97 contained 11 fixes). Fixed builds are 155.0.8059.39/.40 on Windows and macOS and 155.0.8059.39 on Linux, rolling out over days to weeks, with corresponding mobile releases.

Four bugs are rated Critical by the Chromium security team, all use-after-free (CWE-416): CVE-2026-106382 (Chromecast), CVE-2026-106197 (Browser), CVE-2026-106358 (Navigation) and CVE-2026-106347 (Track). Per the Debian security tracker, CVE-2026-106382, CVE-2026-106197 and CVE-2026-106358 allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page (i.e. a sandbox escape), while CVE-2026-106347 allows code execution inside the sandbox via a crafted HTML page. Chrome versions prior to 155.0.8059.39 are affected.

Per SecurityWeek, Google discovered the first Critical bug internally; researcher Xinyang Ge reported three Critical flaws and used AI to identify two additional defects. External researchers reported 62 of the fixes, with roughly $33,000 in bounties disclosed and nearly 50 reports lacking published reward amounts. The most common categories across the batch were incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20) and information leak (17).

Google makes no mention of in-the-wild exploitation, no public PoC is cited in the sources, and no CVSS scores or detailed attack vectors were published at the time of research. This is a patch-prioritization item for a widely deployed browser rather than an active-exploitation campaign. As of the Debian tracker snapshot, distro Chromium packages (150.0.7871.100 and 154.0.8037.92 in bookworm, trixie, forky, sid) were still listed as vulnerable with no fixed version.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1204.001 User Execution: Malicious Link
- T1189 Drive-by Compromise
- T1211 Exploitation for Defense Evasion

## Sources

- [Chrome 155 Update Patches 247 Vulnerabilities (SecurityWeek)](https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/)
- [Stable Channel Update for Desktop (Chrome Releases)](https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html)
- [Google releases Chrome 155 with 247 security fixes, four of them rated critical (BleepingComputer)](https://www.bleepingcomputer.com/forums/t/819180/google-releases-chrome-155-with-247-security-fixes-four-of-them-rated-critical/)
- [Debian Security Tracker: CVE-2026-106382](https://security-tracker.debian.org/tracker/CVE-2026-106382)
- [Debian Security Tracker: CVE-2026-106197](https://security-tracker.debian.org/tracker/CVE-2026-106197)
- [Debian Security Tracker: CVE-2026-106358](https://security-tracker.debian.org/tracker/CVE-2026-106358)
- [Debian Security Tracker: CVE-2026-106347](https://security-tracker.debian.org/tracker/CVE-2026-106347)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3251
