Google Patches Critical Use‑After‑Free Flaws in Chrome & ChromeOS (CVE‑2026‑106197, CVE‑2026‑106358, CVE‑2026‑106240)
Google released stable updates for Chrome and ChromeOS that fix 247 security issues, including four Critical use‑after‑free and type‑confusion vulnerabilities. Organizations must verify patch deployment to maintain audit‑ready evidence of vulnerability management.
ADTP Breach Watch· October 7, 2026· Malwarebytes Labs
On October 6 2026 Google issued stable‑channel updates for Chrome (v155.0.8059.39 on Linux, v154.0.8037.39/40 on Windows/macOS) and ChromeOS (v155.0.8059.39). The releases contain 247 fixes, notably four Critical CVEs (CVE‑2026‑106197, CVE‑2026‑106358, CVE‑2026‑106240) that enable remote code execution outside the browser sandbox.
Why it matters for trust and compliance
The incident underscores the need for a documented, continuously monitored patch‑management process that produces verifiable evidence for control‑assurance frameworks.
Enable automatic updates and capture version logs as continuous control evidence.
Map patch‑status to your framework of record to demonstrate due‑diligence during audits.