Google has released Chrome 155 with fixes for 247 security vulnerabilities, including four critical use-after-free flaws affecting core browser components.
The update is rolling out as Chrome 155.0.8059.39/.40 for Windows and macOS and version 155.0.8059.39 for Linux.
Google has not said that any of the vulnerabilities are currently being exploited in real-world attacks.
The unusually large security update highlights both the complexity of modern browsers and the growing role of artificial intelligence in vulnerability discovery.
Two of the critical bugs were found with assistance from Anthropic’s Claude AI.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Four Critical Vulnerabilities Patched
All four critical vulnerabilities are use-after-free flaws.
The first, CVE-2026-106382, affects Chrome’s Chromecast component and was discovered internally by Google.
CVE-2026-106197 affects the Browser component and was reported by security researcher Xinyang Ge.
The remaining two critical bugs, CVE-2026-106358 in Navigation and CVE-2026-106347 in Track, were also reported by Ge.
Google’s release notes specifically say Claude assisted in finding the latter two vulnerabilities.
A use-after-free vulnerability occurs when software continues using a section of memory after it has already been released.
If manipulated successfully, this type of flaw can lead to crashes, memory corruption or, in serious cases, execution of attacker-controlled code.
AI Helped Researchers Find Critical Chrome Bugs
The Chrome 155 update is notable because AI-assisted vulnerability discovery appears directly in Google’s official security acknowledgements.
Xinyang Ge, who reported three of the four critical bugs, used Claude to assist in identifying two of them.
SecurityWeek reported that Ge was also responsible for roughly a dozen other vulnerabilities addressed in the same release, many of which were found using AI-assisted techniques.
Google has been increasingly examining how AI changes vulnerability research.
The company said in September that AI-discovered vulnerabilities are beginning to alter both the pace and profile of security research, including finding bugs with potentially serious consequences.
The Chrome 155 release provides a practical example of that trend.
53 High-Severity Bugs Also Fixed
The update also resolves 53 high-severity vulnerabilities.
According to SecurityWeek, 34 of those were reported by external security researchers.
The remaining 190 fixes are classified as medium or low severity.
The vulnerabilities cover a wide range of technical weaknesses.
The most common categories include incorrect authorisation, missing authorisation checks, use-after-free bugs, information leaks, uninitialised resources, user-interface misrepresentation and improper input validation.
That variety shows that browser security is not dominated by one type of bug.
Modern browsers contain multiple engines, communication layers, media systems, user-interface components and sandboxed processes, creating a large attack surface.
External Researchers Found 62 of the Security Issues
Google says external security researchers reported 62 of the vulnerabilities addressed in Chrome 155.
SecurityWeek reported that roughly $33,000 in bug-bounty rewards has been disclosed so far.
Payments for many other reports have not yet been announced.
Bug-bounty programmes allow independent researchers to report security weaknesses directly to technology companies before attackers discover them.
The company can then patch the flaw before detailed technical information becomes widely available.
Google also temporarily restricts access to some bug details until most users have received the security update.
No Known Active Exploitation So Far
Unlike some emergency Chrome releases, Google has not said that attackers are exploiting any of these vulnerabilities in the wild.
SecurityWeek similarly noted that Google’s advisory contains no mention of active exploitation.
That does not mean users should delay updating.
Once security fixes become public, attackers can compare older and newer software versions to understand what changed.
This process, sometimes called patch diffing, can help attackers reconstruct a vulnerability even when the vendor initially withholds detailed technical information.
The risk therefore increases as time passes and unpatched browsers remain online.
Chrome Updates Often Install Automatically
Chrome normally downloads updates automatically in the background.
However, the new version does not fully take effect until the browser is restarted.
Users who keep Chrome open for days or weeks may therefore remain on an older vulnerable version even after the update has already downloaded.
The current stable release for Windows and macOS is 155.0.8059.39/.40, while Linux is receiving 155.0.8059.39.
Users can check their version by opening Chrome settings and navigating to the About Chrome section.
The browser will automatically check for an available update and prompt for a restart if necessary.
Android Receives the Same Core Security Fixes
Google also said the corresponding Android release contains the same security fixes as the desktop versions unless otherwise noted.
That means mobile users should also ensure their Chrome installation is updated through the Google Play Store.
The rollout may take several days or weeks to reach every device.
Users should therefore check manually rather than assume the newest version is already installed.
Four Critical Bugs Do Not Mean Four Confirmed Attacks
Critical severity describes the potential impact of a vulnerability.
It does not mean a flaw has already been used to compromise users.
In this case, Google has disclosed no evidence of active exploitation.
The distinction matters because critical vulnerabilities can remain undiscovered by attackers or may require specific technical conditions before exploitation becomes practical.
At the same time, critical ratings indicate that organisations should prioritise the update.
AI Is Changing Vulnerability Research
The role of Claude in discovering two critical Chrome bugs points to a wider change in cybersecurity.
AI systems are increasingly being used to analyse code, identify suspicious patterns and help security researchers test possible vulnerabilities.
That can accelerate defensive research.
But the same capabilities may eventually make it easier for attackers to search for vulnerabilities at scale.
The cybersecurity challenge is therefore becoming less about whether AI can find bugs and more about who finds them first.
Google and other technology companies are increasingly experimenting with AI-assisted vulnerability research while also trying to prevent automated systems from flooding bug-bounty programmes with inaccurate reports.
Browsers Remain High-Value Targets
Chrome is one of the most widely used software applications in the world.
Browsers handle passwords, cookies, authentication sessions, financial websites, cloud applications and other sensitive data.
A successful browser exploit can therefore provide attackers with a valuable foothold inside a user’s computer.
That makes browser vulnerabilities especially important even when no active exploitation has yet been observed.
Keeping the browser current remains one of the simplest protections available to ordinary users and organisations.
What this means for you
Restart Chrome and make sure it has updated to version 155.0.8059.39/.40 on Windows or macOS, or 155.0.8059.39 on Linux. Google has not reported active exploitation, but public disclosure of critical flaws means unpatched browsers become increasingly risky over time.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics