Source: Chrome Releases blog, gHacks
Google has released Chrome 155 to the Stable channel, and the security haul is unusually large: 247 vulnerabilities fixed, with four rated critical, 53 rated high, 122 medium and 68 low. For comparison, the October 1 update to Chrome 154 contained 11 fixes. The new version is 155.0.8059.39/.40 on Windows and Mac and 155.0.8059.39 on Linux, with matching Android and iOS releases rolling out through their respective stores.
The four critical bugs
All four critical issues are use after free flaws, a memory corruption class that frequently ends in arbitrary code execution. They sit in the Chromecast component (CVE-2026-106382), the Browser (CVE-2026-106197), Navigation (CVE-2026-106358) and Track (CVE-2026-106347). Notably, two of the critical reports came from Xinyang Ge of Anthropic, assisted by Claude, a sign of how seriously AI assisted vulnerability discovery has entered mainstream browser security. Among the high severity entries, Google lists a 5,000 dollar bounty for an incorrect authorization issue in Site Isolation (CVE-2026-102322), with other high severity fixes covering the ANGLE graphics layer, Autofill, the Omnibox, Translate and Chrome for iOS.
Why the rollout race matters
Google keeps bug details and links restricted until a majority of users run the fixed version, and restrictions last even longer when a bug lives in a third party library that other projects have not yet patched. That silence is a double edged sword: attackers cannot read the details either, but defenders cannot assess exposure precisely either. The Chrome Releases blog does not say whether any of the 247 vulnerabilities have been exploited in the wild. Because the rollout is gradual, some desktop installations will not receive Chrome 155 right away, which means an unpatched fleet can linger for weeks. The extended stable channel also moved to version 152.0.7977.158 for organizations on the slower cadence.
What to do this week
Treat browser patching as fleet management rather than a per user chore. Verify that your endpoint tooling reports Chrome versions, force or nudge updates to 155, and check that any Chrome based embedded applications or kiosk builds are on a supported update path. For regulated European environments, a documented browser patch SLA is also a cheap way to evidence hygiene under NIS2 and related frameworks.
If managing browser and endpoint patching across your organization has become a bottleneck, contact Excello Digital at https://excello.digital/contact/. We design pragmatic patch management and endpoint security processes that fit European compliance requirements without slowing your teams down.
