Quick answer: Google released Chrome 155 to the Stable channel on October 6, 2026 with 247 security fixes. Desktop builds are 155.0.8059.39/.40 for Windows and macOS and 155.0.8059.39 for Linux. Google publicly highlighted four critical use-after-free vulnerabilities in Chromecast, Browser, Navigation and Track. Chrome for Android receives the same security fixes unless Google notes otherwise.
Because Chrome updates roll out over days or weeks, the important action is not merely knowing the release exists. Check the version installed on each device and restart the browser after the update so the fixed build is actually running.
Chrome 155 stable versions
| Platform | Stable version | Rollout |
|---|---|---|
| Windows | 155.0.8059.39/.40 | Rolling out |
| macOS | 155.0.8059.39/.40 | Rolling out |
| Linux | 155.0.8059.39 | Rolling out |
| Android | 155.0.8059.39 | Rolling out through Google Play |
Google’s Chrome Releases blog is the primary source. AVARIXO also follows software and security releases in AI & Tech.
What are the four critical Chrome 155 CVEs?
| CVE | Component | Type |
|---|---|---|
| CVE-2026-106382 | Chromecast | Use after free |
| CVE-2026-106197 | Browser | Use after free |
| CVE-2026-106358 | Navigation | Use after free |
| CVE-2026-106347 | Track | Use after free |
Use-after-free bugs involve software continuing to reference memory after it has been released. Their real-world exploitability depends on the exact bug and mitigations in place, but Google classified these four as Critical, which makes the browser update a priority.
Google’s public release note does not say that these four named critical CVEs are being exploited in the wild. That is different from saying exploitation is impossible. Browser vulnerability details are often restricted until enough users have updated, specifically to reduce the window for attackers to study an unfixed population.
Why “247 security fixes” is bigger than the public CVE list
The release post says the update contains 247 security fixes, while the visible list highlights selected issues and externally reported bugs. Not every change receives a public CVE description at release time, and some bug links stay restricted until the update reaches a majority of users.
That means administrators should use the target Chrome version as the compliance test rather than trying to count visible CVEs one by one. If the endpoint is still on Chrome 154 or an earlier 155 build, it has not necessarily received the complete Stable-channel security package.
How to update Chrome 155 on Windows, Mac and Linux
- Open Chrome.
- Open the three-dot menu.
- Select Help > About Google Chrome.
- Allow Chrome to check for and download the update.
- Click Relaunch when prompted.
- Return to the About page and verify the installed version.
On managed enterprise systems, a browser policy or software-management platform may control the rollout. Administrators should verify the fleet’s reported browser version rather than assuming Google’s staged rollout has reached every endpoint.
How to update Chrome 155 on Android
Google says Android releases contain the same security fixes as the corresponding desktop release unless otherwise noted. On Android:
- Open Google Play.
- Search for Google Chrome or open the app-management page.
- Tap Update if it is available.
- Close and reopen Chrome after installation.
- Check Chrome’s version information if you manage a security-sensitive device.
If Google Play still shows no update, the staged rollout may not have reached the device yet. Keep automatic updates enabled and check again rather than sideloading an untrusted package.
What enterprise teams should verify
- Installed version: report the executable version, not just update-policy status.
- Restart state: Chrome can download an update but continue running old code until relaunch.
- Browser forks: Chromium-based browsers have their own release schedules; a Chrome fix does not prove another vendor has shipped its corresponding update.
- VDI and shared systems: verify golden images as well as active sessions.
- Android fleet: mobile-device management reports may lag behind Play Store rollout, so validate actual package version where possible.
Should you wait for more CVE details?
No. Google’s own release note makes clear that details may remain restricted until a majority of users have a fix. Waiting for proof-of-concept information would invert the purpose of that restriction. The safer order is update first, investigate individual vulnerability mechanics later if your threat model requires it.
FAQ
How many security fixes are in Chrome 155?
Google says the October 6 Stable update includes 247 security fixes.
What Chrome 155 version should Windows users have?
Google lists 155.0.8059.39/.40 for Windows.
What version should Linux users have?
Google lists 155.0.8059.39 for Linux.
Does Android get the same security fixes?
Google says Android releases contain the same security fixes as corresponding desktop releases unless otherwise noted.
Are the four critical bugs confirmed exploited?
Google’s public release post does not identify in-the-wild exploitation for those four named CVEs.
Sources checked October 7, 2026: Google’s Chrome Releases blog and current first-page security coverage.
