SecurityWeek reported that Google released a Chrome 155 security update on Tuesday. It fixes 247 vulnerabilities, and four are rated critical. All four are use-after-free bugs, where a program keeps using memory it has already released. They affect the Chromecast, Browser, Navigation and Track components. Google found one. Researcher Xinyang Ge reported the other three and used AI to find two. SecurityWeek, citing Google's advisory, says the update also fixes 53 high-severity flaws, 34 of them from outside researchers. The other 190 are medium or low severity. The builds are 155.0.8059.39 and .40 for Windows and macOS, and .39 for Linux.
Some details are still open. Google has not said what it paid Ge for the critical bugs. It has also not given reward amounts for almost 50 of the 62 reports from outside researchers. SecurityWeek says the payments so far add up to roughly $33,000. Ge reported about a dozen of the high-severity flaws, and Google will not reward some of them. SecurityWeek says Google does not mention any of the flaws being used in attacks.
Anyone who runs Chrome on desktops, or manages it across a company, has a large batch of fixes to roll out. The update covers Windows, macOS and Linux. The report also shows AI helping a researcher find some of these bugs.