Google promoted Chrome 155 to the Stable channel on 7 October 2026 with 247 security fixes. Four are critical use-after-free bugs scored 9.6, in Chromecast, the browser process and navigation, alongside an incorrect-authorisation flaw in Site Isolation. At least 53 more are rated high.

None of them is reported as exploited in the wild.

247 is not a normal number

A Chrome release usually carries somewhere between ten and forty security fixes. This one carries 247.

That is not a statement about Chrome getting worse. Nothing in the advisory suggests a collapse in code quality, and the absence of any in-the-wild exploitation is the tell: these are bugs found by people looking, not bugs found by victims.

Something changed on the finding side, and the release notes say what.

What the credits show

Reporting on Google's attribution list describes a pattern worth reading carefully: twelve entries are credited to a single researcher at Anthropic working with assistance from the company's model, and two more come from OpenAI Codex Security. Google found one of the critical use-after-free bugs internally.

Twelve findings in one release from one researcher-and-tool pairing is the detail. It is not a claim that a model found bugs unaided — the credit is to a person, assisted — and it is one release's notes rather than a study. Taken at that altitude, it still says something: AI-assisted research now accounts for a visible, countable share of what reaches a major vendor's security queue.

This is the second time in a week we have written about it from a different direction. Horizon3 used a model to find the Rejetto HFS flaw where a weak generator and a leaky code path only mattered together — and what the tool contributed there was the connection between two distant parts of a codebase, which is exactly what a human reviewer runs out of attention for.

The number everyone quoted, explained

Microsoft's report last week put nearly 40,000 CVEs in the first half of 2026, on a pace to roughly double previous annual totals. That figure was widely read as the world getting more dangerous.

Chrome 155 is what the figure looks like at the level of one product. The software is not newly broken. Finding flaws in it got cheaper, and the output of cheaper finding is a larger number of published vulnerabilities.

Which direction that cuts depends entirely on who is doing the finding. A bug reported to Google and fixed before anyone uses it has been removed from the world. The same capability pointed the other way produces a bug nobody reports.

Where it lands badly

For a vendor, 247 fixed bugs is an unambiguously good release. For everyone downstream, the consequences are more awkward.

Vulnerability feeds, scanners and compliance processes consume CVEs at whatever rate they are produced, and the people triaging them are the same number of people as last year. A tenfold increase in published flaws with no increase in triage capacity means prioritisation stops being a discipline and starts being a lottery — and the thing most likely to be missed is the ordinary high-severity bug buried under 200 others.

One small number says the rest. The largest bounty listed in this release is 5,000 dollars. When finding a bug was expensive, it was worth a great deal. The price is a measure of scarcity, and scarcity is what changed.

What to do

  • Update Chrome and restart it. The fix is in 155.0.8059.39 and later; a browser left open for days has not applied it.
  • Check the fleet, not your own machine. Managed estates lag, and four critical use-after-free bugs in the browser process is not a lag worth carrying.
  • Do not read the count as risk. Two hundred and forty-seven fixes with no exploitation is a healthy release, and treating volume as severity will exhaust whoever is doing your triage.
  • If you run a vulnerability programme, plan for the rate rather than this release. The thing to fix is the process that assumed a few dozen CVEs a week.

What is not established

  • Exactly how the AI-assisted findings were produced, which neither Google nor the researchers have detailed.
  • What share of the 247 are AI-assisted overall, as opposed to the entries that name it.
  • Whether this release size is the new normal for Chrome or an unusually large batch.
  • Whether any of these flaws were independently known to anyone who did not report them.