Chrome 155 Requires Build and Extension Policy Checks
Google released Chrome 155 on 6 October 2026. Its desktop rollout spans days or weeks, so verify the version loaded after restart.
Four critical fixes set the minimum
Desktop targets are 155.0.8059.39/.40 on Windows and macOS and 155.0.8059.39 on Linux. Android also uses 155.0.8059.39 and carries corresponding desktop fixes unless noted otherwise.
Google lists 247 fixes and four critical use-after-free flaws:
- CVE-2026-106382, Chromecast;
- CVE-2026-106197, Browser;
- CVE-2026-106358, Navigation; and
- CVE-2026-106347, Track.
Google’s bulletin does not make an in-the-wild exploitation claim.
Managed extensions need a separate compatibility check
On managed browsers, chrome.debugger.attach() is rejected on every target if an extension has a non-empty runtime_blocked_hosts list, even when runtime_allowed_hosts contains an origin. DisableScreenshots or data loss prevention restrictions can also reject attachment.
Unmanaged browsers and managed environments without those restrictions are unchanged. This is a policy boundary, not evidence that an extension is malicious or broken everywhere.
Verify the build and the workflow
- Record the running version. Check after restart and compare the result with the target for that operating system.
- Find approved debugger users. Identify internal or approved extensions that request direct debugger access and assign an owner to each workflow.
- Map the actual restrictions. Record the controls that apply to each approved extension. A generic managed-browser label is not enough.
- Exercise the normal workflow. Use the existing validation ring and record any attachment rejection with the extension owner. Do not weaken a security policy merely to make the error disappear.
- Separate mobile verification. Confirm Android deployment through its own management channel rather than borrowing a desktop result.
These are BlackTree editorial recommendations, not completed extension tests or Google instructions.
BlackTree’s Chrome 154 analysis explains the same version-certainty problem for an earlier release. Its builds and vulnerabilities must not be reused for Chrome 155.


