Vulnerabilities

Chrome Fixes 1,072 Security Bugs with AI

July 30, 2026 20:07 · 12 min read
Chrome Fixes 1,072 Security Bugs with AI

AI-Powered Security Bug Fixes in Chrome

Google has announced that its use of artificial intelligence (AI) in the Chrome browser's vulnerability management process has led to a significant increase in the number of security bugs fixed. According to Google, Chrome 149 and Chrome 150 fixed 1,072 security bugs, surpassing the total number fixed in the previous 23 Chrome milestones combined.

Large Language Models in Vulnerability Management

Google now uses large language models (LLMs) throughout the vulnerability management process, including discovering flaws, reproducing reports, determining severity, assigning bugs to developers, generating candidate patches, and creating tests. This expanded use of AI has dramatically increased the number of security vulnerabilities that can be found and fixed in Chrome.

Google began using LLMs to improve security fuzzing in 2023, before collaborating with Project Zero on Naptime, a system that provided AI models with specialized vulnerability research tools. The company later worked with Google DeepMind and Project Zero on Big Sleep, an AI-powered vulnerability discovery agent that found flaws in Chrome's V8 JavaScript engine and graphics components.

Recent Security Bug Fixes and Discoveries

One vulnerability discovered by the system was a Chrome sandbox escape that had remained in the codebase for more than 13 years. If exploited, the flaw would have allowed a compromised renderer to escape the sandbox and trick the browser into reading local files.

Google is also encouraging its developers to add SECURITY.md files describing trust boundaries and threat models, helping its AI systems better identify operations with security implications. The company says its multi-agent AI workflows help rather than replace existing security testing, including fuzzing, which remains effective at discovering complex vulnerabilities.

Automating Vulnerability Triage and Patching

Google has seen a sharp increase in reports submitted through the Chrome Vulnerability Reward Program, and by March 2026, the company had received more security bug reports than during all of 2025. To prioritize these reports, Google modified its program to focus on reports that add to what its already finding and processing through its automated tooling.

The company is also automating vulnerability triage, including filtering spam and duplicates, reproducing proof-of-concept exploits, assigning severity ratings, and routing reports to the appropriate developers. Google estimates that this automated process saves hundreds of hours of developer time each month.

Delivering Patches to Users

After a vulnerability is confirmed, fixing agents generate multiple potential patches, while another agent evaluates the proposed fixes and produces additional information for developers to review. In May, these systems reportedly prevented more than 20 vulnerabilities from reaching production, including one issue classified as critical.

However, Google notes that finding and fixing vulnerabilities more quickly also requires accelerating how patches are delivered to users. Once a security fix is committed to Chrome's public source code, attackers can inspect the change and attempt to reverse-engineer the vulnerability before the update reaches users.

Future Plans for Chrome Updates

Google is transitioning Chrome to a two-week major release cycle with weekly security updates and is piloting two security releases per week to reduce this patch gap. To reduce disruptions, the company is developing 'dynamic patching,' which would allow Chrome to apply updates without restarting the browser.

Starting with Chrome 150 on macOS, the browser can automatically restart to apply a pending update when it is running in the background without any open windows. Google says its long-term goal is to keep Chrome continuously updated through dynamic patching, automatic restarts during periods of inactivity, and improved session restoration.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free