Desktop update ships for Windows, macOS and Linux
Google has released a Chrome Stable desktop update containing 247 security fixes. The Chrome Releases advisory identifies four critical and 53 high-severity issues by CVE.
SecurityWeek classifies the remaining 190 fixes as medium or low severity. Its report on the rollout lists these versions:
- Windows and macOS: Chrome 155.0.8059.39/.40
- Linux: Chrome 155.0.8059.39
Those platform-specific build numbers come from SecurityWeek. They do not appear in the supplied excerpt of Google’s advisory.
Google is temporarily limiting access to some bug records and links. The company says restrictions may remain until most users have updated, or when a vulnerability exists in a third-party library used by other projects that have not yet fixed it.
Three critical flaws permit code execution outside the sandbox
Google assigned critical severity to four use-after-free vulnerabilities affecting Chromecast, Browser, Navigation and Track. Their NVD records classify the underlying weakness as CWE-416.
All four affect Google Chrome versions before 155.0.8059.39 and can be triggered through crafted HTML pages. Their documented impacts differ:
| CVE | Component | Documented impact | CVSS |
|---|---|---|---|
| CVE-2026-106382 | Chromecast | Arbitrary code execution outside the sandbox | 9.6 |
| CVE-2026-106197 | Browser | Arbitrary code execution outside the sandbox | 9.6 |
| CVE-2026-106358 | Navigation | Arbitrary code execution outside the sandbox | 9.6 |
| CVE-2026-106347 | Track | Arbitrary code execution inside the sandbox | 8.8 |
The first three use the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. This describes network-reachable attacks with low complexity and no required privileges, although user interaction is necessary. The changed scope corresponds to the documented ability to execute code outside the sandbox.
CVE-2026-106347 uses CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Its scope remains unchanged, and NVD describes the resulting execution as confined to the sandbox.
Google discovered CVE-2026-106382 and recorded a report date of 2026-07-15. Xinyang Ge reported CVE-2026-106197 on 2026-09-11.
The advisory attributes CVE-2026-106358 and CVE-2026-106347 to Xinyang Ge of Anthropic, assisted by Claude. Their respective report dates are 2026-09-28 and 2026-09-30.
Google displays TBD for the bounties associated with CVE-2026-106197 and CVE-2026-106358. The other two critical entries show N/A; the supplied material does not define those labels further.
High-severity findings show why vendor labels and CVSS differ
The 53 high-severity entries cover components including ANGLE, V8, Media, WebRTC, PDF, Autofill, SiteIsolation, Core, Fonts and WebAudio. They include use-after-free defects, race conditions, authorization failures, type confusion, integer overflows and uninitialized resources.
A Chromium severity label is not a CVSS score. Two high-severity examples demonstrate the distinction.
CVE-2026-102322 is an incorrect-authorization vulnerability in SiteIsolation, categorized as CWE-863. Although Chromium labels it high severity, it has a CVSS score of 9.6 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H.
According to NVD, a remote attacker could use crafted HTML to execute arbitrary code. Avadhut Mahamuni reported the issue on 2026-06-23, and Google lists a $5,000 bounty.
CVE-2026-106245, meanwhile, is also rated high by Chromium but has a CVSS score of 4.3. This CWE-908 uninitialized-resource flaw in ANGLE could expose cross-origin data through crafted HTML. JonathanBouman reported it on 2026-08-21, with a listed reward of $2,000.
Other high-severity findings have specific prerequisites or platform scope:
- CVE-2026-106327 is an incorrect-authorization defect in Core. NVD says an attacker must already have compromised the renderer process before using crafted HTML to bypass system access restrictions.
- CVE-2026-106366 is an incomplete-cleanup issue in CustomTabs affecting Chrome on Android before 155.0.8059.39. Its documented consequence is a web-origin policy bypass through crafted HTML.
The Windows, macOS and Linux builds reported for this release should not be extrapolated into Android deployment guidance. The supplied information does not identify an Android rollout build.
AI assistance appears across critical and high-severity reports
Google explicitly credits Claude with assisting Xinyang Ge on the critical Navigation and Track vulnerabilities. Similar attribution appears on several high-severity reports submitted from 2026-09-24 through 2026-09-30.
Those reports include use-after-free bugs in Select, Metrics, Media, Parser, WebRTC, V8 and PDF. OpenAI Codex Security is separately credited for CVE-2026-106257, a use-after-free issue in HTML, and CVE-2026-106240, a V8 type-confusion vulnerability.
SecurityWeek reports that external researchers submitted 62 bugs covered by the update. They accounted for 34 of the 53 high-severity issues.
According to the publication, Google paid approximately $33,000 in rewards, while amounts associated with almost 50 reports had not yet been disclosed. Individual entries in Google’s advisory display dollar values, TBD or N/A.
Across all 247 fixes, the most frequently represented categories were incorrect authorization with 41 issues, use after free with 34, and missing authorization with 34. Other counts include UI misrepresentation at 20, information leak at 17, uninitialized resource at 16, confused deputy at nine, and improper input validation at nine.
The supplied category totals do not map those counts to individual CVEs or severity levels.
No evidence of active exploitation is presented
SecurityWeek says Google’s advisory did not mention exploitation in the wild. That is not equivalent to confirmation that exploitation has been ruled out.
CVSS measures technical properties and potential impact, while Chromium’s critical and high labels represent vendor severity assessments. Neither establishes whether attackers are currently using a vulnerability.
The documented consequences are nevertheless substantial. Three critical vulnerabilities have CVSS scores of 9.6 and can permit execution outside Chrome’s sandbox after user interaction with crafted HTML. The fourth critical issue allows execution inside the sandbox.
No EPSS probabilities are included in the supplied data. There is also no cited evidence here placing any of these vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog.
Install the relevant stable build
Windows and macOS users should update to Chrome 155.0.8059.39/.40. Linux users should install 155.0.8059.39.
For managed environments, administrators should verify that endpoints have received the appropriate stable build rather than relying solely on automatic rollout. This is especially relevant for systems that regularly handle untrusted web content.
The supplied reporting identifies installation of the updated builds as the available mitigation. The excerpt of Google’s advisory does not provide an additional workaround, but because other sections were omitted, that does not establish whether Google published further guidance elsewhere.
Some vulnerability details may remain restricted during deployment. Defenders should not wait for complete technical disclosure before updating supported desktop systems.




