Chrome 155 update patches 247 flaws, four critical
Google has released Chrome 155, a security update that fixes 247 vulnerabilities. Four of them are rated critical. The new version began rolling out to users on Tuesday.
The size of the release is not the only notable thing about it. A large number of the externally reported bugs came from one researcher, Xinyang Ge, and many of those bugs were found with the help of AI.
Four critical use-after-free bugs
All four critical flaws are use-after-free issues. This type of memory bug happens when software keeps using a piece of memory after it has already been freed. The affected components are Chromecast, Browser, Navigation and Track. The flaws are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358 and CVE-2026-106347.
Google found the first of these, CVE-2026-106382, on its own. Xinyang Ge reported the other three and used AI to identify two of them. Google has not yet said how much it paid the researcher for these reports.
High-severity fixes and AI-assisted findings
The update also fixes 53 high-severity vulnerabilities. According to Google's advisory, external researchers reported 34 of them.
Xinyang Ge reported roughly a dozen of these high-severity bugs. Many were found with AI, and Google says it will not pay the researcher a reward for some of them. The company has not said which reports are excluded or why.
The other 190 flaws are rated medium or low severity. Google's own teams found most of them.
Bounty payouts still incomplete
In total, external researchers reported 62 of the bugs fixed in Chrome 155. Google has paid about $33,000 in bug bounty rewards so far. It has not yet disclosed the amounts for almost 50 of those reports, so the final total could change.
Authorization problems top the list
Access control mistakes make up the largest group of fixes. The update addresses:
- 41 incorrect authorization flaws
- 34 use-after-free bugs
- 34 missing authorization issues
- 20 UI misrepresentation flaws
- 17 information leaks
- 16 uninitialized resource bugs
- 9 confused deputy issues
- 9 improper input validation flaws
Google does not say that any of these vulnerabilities have been exploited in the wild.
Versions to look for
Chrome 155 is rolling out as versions 155.0.8059.39/.40 on Windows and macOS, and as version 155.0.8059.39 on Linux. Users and administrators should check that browsers in their environment are running these builds, especially given the number of critical and high-severity fixes.
The release follows Google's October 2026 Android update, which fixed 25 flaws, seven of them critical.
Why It Matters
With no known exploitation, Chrome 155 is not an emergency patch. But 57 critical and high-severity fixes in a single release is a large attack surface to leave open, and a browser is software that almost every organization exposes to untrusted content every day. Installing the update soon is the sensible choice.
The more telling detail is the role of AI. One researcher using AI accounts for three of the four critical bugs and about a dozen high-severity ones. That suggests AI-assisted bug hunting is now producing valid, serious findings in a heavily tested codebase, not just noise. Google's decision to withhold rewards for some of these reports fits a wider tension. The company recently paused its open-source bug bounty because of a wave of AI-generated submissions. At the same time, a Rejetto HFS flaw found by AI has already been exploited in attacks.
It will be worth watching whether Google explains how it values AI-assisted reports under its Chrome program, and whether other vendors set similar rules. If AI tools keep surfacing bugs at this pace, larger patch releases may become more common, and defenders could have less time between disclosure and exploitation.
