Google Chrome 155.0.8059.39/.40 Patches 247 Security Issues Including Two Critical Use-After-Free Bugs
Chrome's Stable channel moves to 155.0.8059.39/.40 (Windows/Mac) and 155.0.8059.39 (Linux), bundling 247 security fixes, including two critical use-after-free vulnerabilities in Chromecast and the browser core.
Google has released Chrome 155.0.8059.39/.40 for Windows and Mac, and 155.0.8059.39 for Linux, through the Stable channel, with the rollout continuing over the coming days and weeks. This build carries a large security payload — 247 fixes in total — making it a priority update for anyone running Chrome on desktop. Two of the publicly disclosed issues are rated Critical, Google's highest severity tier, reserved for flaws that can lead to sandbox escape or full system compromise.
What's in this release
This Stable channel build addresses 247 security fixes, a notably large batch even by Chrome's regular release cadence. Google has disclosed details for two Critical-severity vulnerabilities so far: CVE-2026-106382, a use-after-free bug in the Chromecast component reported to Google on 2026-07-15, and CVE-2026-106197, a use-after-free bug in the core Browser process reported by external researcher Xinyang Ge on 2026-09-11. Use-after-free vulnerabilities are a well-known class of memory-safety bug that can potentially be leveraged for arbitrary code execution, which is why both are classified as Critical. As is standard practice, Google is withholding bug details and links for many of the remaining fixes until a majority of users have updated, and may keep restrictions longer where a fix touches a third-party library shared with other projects.
Why it matters for your stack
Because Chrome is widely deployed across desktop environments and embedded in many workflows (including via Chromium-based browsers and Electron apps that track upstream security fixes), a release with this many security patches — and two Critical-rated issues already disclosed — warrants prompt attention. Organizations managing Chrome at scale through enterprise policies should treat this as a priority push rather than a routine update cycle.
How to update
Chrome generally updates itself automatically in the background; users can confirm they're on the latest build via Settings > About Chrome, which also triggers a check and prompts a restart if an update was applied. IT administrators managing fleets through Chrome Browser Cloud Management or similar tools should verify that the 155.0.8059.39/.40 build has been pushed and confirm rollout completion over the coming days, since Google notes the update will roll out progressively across Windows, Mac, and Linux.
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email