Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws, across Windows, Mac, and Linux.

The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google’s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution.

The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the use-after-free issue on July 15, 2026. The second, CVE-2026-106197, affects the Browser component and security researcher Xinyang Ge reported on September 11, 2026.

CVE-2026-106358 affects Navigation and was reported on September 28, 2026. CVE-2026-106347 affects Track and was reported on September 30, 2026.

Google credits Xinyang Ge of Anthropic, assisted by Claude, for both discoveries, highlighting AI assistance in the vulnerability research process.

All 4 critical entries share the same underlying weakness category: use-after-free. This category concerns software accessing memory after it has been released.

Critical Flaws :

CVE Affected component Vulnerability Reported by
CVE-2026-106382 Chromecast Use after free Google
CVE-2026-106197 Browser Use after free Xinyang Ge
CVE-2026-106358 Navigation Use after free Xinyang Ge, Anthropic, assisted by Claude
CVE-2026-106347 Track Use after free Xinyang Ge, Anthropic, assisted by Claude

However, the advisory does not establish whether these particular flaws permit a sandbox escape, require user interaction, or can be combined into a working attack chain.

Chrome Update Fixes Massive 247 Vulnerabilities

Google has not explicitly stated that these vulnerabilities are being exploited in the wild. That absence should not be interpreted as proof that exploitation has never occurred.

The update also addresses high severity flaws across graphics, media, browser interfaces, and security controls. CVE-2026-102322 involves incorrect authorization in SiteIsolation, while CVE-2026-106239 concerns an integer overflow in WebGL. Several ANGLE vulnerabilities involve uninitialized resources, alongside type confusion and use-after-free issues.

The V8 engine receives fixes for race conditions, type confusion, and use-after-free. Other affected components include WebRTC, WebAudio, PDF, Storage, Autofill, Fonts, and DevTools. Medium- and low-severity entries cover information leaks, missing authorization, misleading interfaces, and additional resource-handling weaknesses.

Google says many security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. These tools form part of the company’s broader security testing effort.

Google warns that access to bug details may remain restricted until most users have installed fixes. Restrictions can also continue when a vulnerability affects a third-party library used by other projects that have not yet patched it.

For organizations tracking remediation, the announced version numbers provide a clear reference for checking deployment progress. The staged rollout means availability may differ between systems. Security teams should distinguish the confirmed fixes from unverified claims about exploitability when communicating this release’s risk to users and administrators.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws appeared first on Cyber Security News.