Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe
155.0.8059.39
RELEASE SECURITY Browsers Google Chrome · released October 6, 2026 · covered October 6, 2026

Google Chrome 155.0.8059.39/.40 Patches 247 Security Issues Including Two Critical Use-After-Free Bugs

Chrome's Stable channel moves to 155.0.8059.39/.40 (Windows/Mac) and 155.0.8059.39 (Linux), bundling 247 security fixes, including two critical use-after-free vulnerabilities in Chromecast and the browser core.

247 security fixes 2 Critical use-after-free CVEs Rolling out on Windows, Mac, Linux
AI summary

Google has released Chrome 155.0.8059.39/.40 for Windows and Mac, and 155.0.8059.39 for Linux, through the Stable channel, with the rollout continuing over the coming days and weeks. This build carries a large security payload — 247 fixes in total — making it a priority update for anyone running Chrome on desktop. Two of the publicly disclosed issues are rated Critical, Google's highest severity tier, reserved for flaws that can lead to sandbox escape or full system compromise.

What's in this release

This Stable channel build addresses 247 security fixes, a notably large batch even by Chrome's regular release cadence. Google has disclosed details for two Critical-severity vulnerabilities so far: CVE-2026-106382, a use-after-free bug in the Chromecast component reported to Google on 2026-07-15, and CVE-2026-106197, a use-after-free bug in the core Browser process reported by external researcher Xinyang Ge on 2026-09-11. Use-after-free vulnerabilities are a well-known class of memory-safety bug that can potentially be leveraged for arbitrary code execution, which is why both are classified as Critical. As is standard practice, Google is withholding bug details and links for many of the remaining fixes until a majority of users have updated, and may keep restrictions longer where a fix touches a third-party library shared with other projects.

Why it matters for your stack

Because Chrome is widely deployed across desktop environments and embedded in many workflows (including via Chromium-based browsers and Electron apps that track upstream security fixes), a release with this many security patches — and two Critical-rated issues already disclosed — warrants prompt attention. Organizations managing Chrome at scale through enterprise policies should treat this as a priority push rather than a routine update cycle.

How to update

Chrome generally updates itself automatically in the background; users can confirm they're on the latest build via Settings > About Chrome, which also triggers a check and prompts a restart if an update was applied. IT administrators managing fleets through Chrome Browser Cloud Management or similar tools should verify that the 155.0.8059.39/.40 build has been pushed and confirm rollout completion over the coming days, since Google notes the update will roll out progressively across Windows, Mac, and Linux.

Synthesized by AI from 1 source · updated 1 hour ago
Sources · merged by AI 1 total
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email