BlackTree Security · Infrastructure · Automation · AI

Chrome 155 Requires Build and Extension Policy Checks

Google released Chrome 155 on 6 October 2026. Its desktop rollout spans days or weeks, so verify the version loaded after restart.

Four critical fixes set the minimum

Desktop targets are 155.0.8059.39/.40 on Windows and macOS and 155.0.8059.39 on Linux. Android also uses 155.0.8059.39 and carries corresponding desktop fixes unless noted otherwise.

Google lists 247 fixes and four critical use-after-free flaws:

Google’s bulletin does not make an in-the-wild exploitation claim.

Managed extensions need a separate compatibility check

On managed browsers, chrome.debugger.attach() is rejected on every target if an extension has a non-empty runtime_blocked_hosts list, even when runtime_allowed_hosts contains an origin. DisableScreenshots or data loss prevention restrictions can also reject attachment.

Unmanaged browsers and managed environments without those restrictions are unchanged. This is a policy boundary, not evidence that an extension is malicious or broken everywhere.

Verify the build and the workflow

  1. Record the running version. Check after restart and compare the result with the target for that operating system.
  2. Find approved debugger users. Identify internal or approved extensions that request direct debugger access and assign an owner to each workflow.
  3. Map the actual restrictions. Record the controls that apply to each approved extension. A generic managed-browser label is not enough.
  4. Exercise the normal workflow. Use the existing validation ring and record any attachment rejection with the extension owner. Do not weaken a security policy merely to make the error disappear.
  5. Separate mobile verification. Confirm Android deployment through its own management channel rather than borrowing a desktop result.

These are BlackTree editorial recommendations, not completed extension tests or Google instructions.

BlackTree’s Chrome 154 analysis explains the same version-certainty problem for an earlier release. Its builds and vulnerabilities must not be reused for Chrome 155.

Leave a Reply

Your email address will not be published. Required fields are marked *