Google released a Chrome desktop security update addressing 247 vulnerabilities, including four critical use-after-free flaws in Chromecast, Browser, Navigation and Track. Google lists four Critical, 53 High, 122 Medium and 68 Low findings; Italy’s ACN advisory reports different severity totals—12 critical and 42 high—for the same update. Patched releases are 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux. Tenable identifies the critical flaws as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358 and CVE-2026-106347, respectively, describing potential code execution outside the sandbox for the first three and inside it for Track. Other fixes cover memory safety, authorization, race conditions, information disclosure and isolation bypasses across components including V8, ANGLE and SiteIsolation. Google credited researchers including Anthropic’s Xinyang Ge, assisted by Claude, for the Navigation and Track discoveries. The supplied Google notice does not report exploitation in the wild or confirm a working attack chain.
Tenable also published numerous Nessus checks flagging vendor-reported unpatched Linux/Unix packages, frequently listing Debian Chromium and stating that no vendor patch or known solution is available for the packages covered. Those distribution-package findings do not mean Google’s Chrome update is unavailable. Several records pair Android-, iOS-, Windows- or macOS-specific vulnerability descriptions with Linux detection metadata, while many CVSS ratings differ substantially from Chromium’s severity assessments or omit described attack prerequisites. These discrepancies leave some platform applicability and prioritization uncertain; the checks rely on package information rather than demonstrated exploitation and report no known available exploits. Organizations should update and restart managed Chrome installations, verify installed versions during the staged rollout, and separately validate Chromium findings against distribution security advisories. Where affected packages cannot be remediated, moving to a supported, patched browser build should be evaluated. Google is restricting some bug details until adoption improves or affected shared libraries are fixed.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Tenable published Nessus checks for vendor-reported unpatched Linux/Unix packages associated with the disclosed Chrome vulnerabilities, listing Debian Chromium packages and no known solution or available exploits. Its descriptions identify outside-sandbox code execution for the critical Chromecast, Browser, and Navigation flaws and inside-sandbox code execution for Track, while several listings contain unresolved platform or severity discrepancies.
Google released Chrome 155.0.8059.39 for Android to a small percentage of users on October 6. The update was not yet available to all users through Google Play.
Google released Chrome 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux, addressing 247 vulnerabilities. Google's security note lists four Critical, 53 High, 122 Medium, and 68 Low flaws; the supplied CSIRT Italia advisory reports a conflicting severity breakdown of 12 critical and 42 high.
Google initially released Chrome 155.0.8059.26/.27 to a small percentage of Windows and Mac users on September 30, 2026. This preceded the wider Stable rollout on October 6.
Xinyang Ge of Anthropic, assisted by Claude, reported CVE-2026-106347, a critical use-after-free vulnerability in Chrome's Track component.
Xinyang Ge of Anthropic, assisted by Claude, reported CVE-2026-106358, a critical use-after-free vulnerability in Chrome's Navigation component.
Xinyang Ge reported CVE-2026-106197, a critical use-after-free vulnerability in Chrome's Browser component.
Google reported CVE-2026-106382, a critical use-after-free vulnerability in Chrome's Chromecast component.
Google reportedly released an update for ChromeOS alongside its Chrome browser updates. The reference does not specify the ChromeOS version, release date, or vulnerabilities addressed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
opennet.ru
Open sourceopennet.me
Open sourceghacks.net
Open sourcesecurityweek.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.