Google fixes 1,072 Chrome security bugs in two releases using AI, pilots twice-weekly updates

Reviewed byNidhi Govil

7 Sources

Share

Google patched 1,072 security bugs in Chrome 149 and 150 using AI-powered tools—surpassing the total from the previous 23 releases combined. The company now pilots twice-weekly security updates and develops dynamic patching to apply fixes without browser restarts, as AI bug hunting transforms cybersecurity defense.

AI Transforms Chrome Security With Record Bug Fixes

Google has patched 1,072 security bugs across Chrome 149 and 150, both released in June, using AI-powered vulnerability discovery tools

1

. This figure exceeds the combined total of 1,036 fixes from the previous 23 Chrome releases spanning two years, marking a dramatic shift in how Chrome security operates

1

. Doug Turner, Chrome's director of engineering, told TechCrunch that large language models have "fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation"

1

.

Source: BleepingComputer

Source: BleepingComputer

Google Deploys Multi-Agent AI Workflows for Vulnerability Management

The company now uses large language models throughout its entire vulnerability management process, from discovering flaws to generating candidate patches . Google created custom Gemini-powered agent harnesses in early 2026 to search Chrome's codebase for vulnerabilities while reducing false positives

5

. The system discovered a high-severity sandbox escape vulnerability that had remained hidden in the codebase for over 13 years

5

. These automated workflows include "fixing agents" that draft potential code patches, "critic agents" that evaluate fixes against Chromium standards, and "test-writing agents" that generate cross-platform test suites

5

. In May alone, these systems blocked over 20 vulnerabilities from reaching production, including one classified as critical

4

.

Source: Wired

Source: Wired

Twice-Weekly Security Updates Pilot Addresses Patch Gap

Chrome is piloting a shift to twice-weekly security updates to shrink the "patch gap"—the window between when a fix is committed to Chrome's public source code and when it reaches users

3

. Once Google publicly discloses and patches a flaw, attackers can reverse-engineer the vulnerability and exploit it before updates reach users' machines

3

. "In the face of fast-moving, AI-powered attacks, our delivery cadence must accelerate even further," Google stated

3

. This builds on Chrome's existing weekly security update schedule and comes ahead of a planned two-week major release cycle launching in September with Chrome 153

3

.

Dynamic Patching Aims for Continuous Updates Without Disruption

Google is developing dynamic patching to apply critical updates without requiring full browser restarts, addressing a key barrier to timely security fixes

3

. The method leverages Chrome's multi-process architecture to hot-swap background processes like the Renderer and GPU on the fly

5

. Starting with Chrome 150 on macOS, the browser can automatically restart to apply pending updates when running in the background without open windows

3

. Google's long-term vision is a browser that remains continuously updated through dynamic patching, automatic restarts during inactivity, and improved session restoration

4

.

Source: PC Magazine

Source: PC Magazine

AI Bug Hunting Reaches Inflection Point Across Cybersecurity

Parisa Tabriz, Chrome's vice president and general manager, told WIRED that while Chrome has used machine learning for fuzz testing since 2012, "this year is very different. It really feels like an inflection point both for offense and defense"

2

. Google began using LLMs to improve security fuzzing in 2023, then collaborated with Project Zero on Naptime and later with Google DeepMind and Project Zero on Big Sleep, an AI-driven vulnerability discovery agent that found flaws in Chrome's V8 JavaScript engine

4

. By March 2026, Google had received more security bug reports than during all of 2025, prompting modifications to its Chrome Vulnerability Reward Program to prioritize reports that add value beyond automated tooling

4

. Microsoft also announced it patched a record 570 security flaws in its monthly Patch Tuesday, citing its own AI usage

1

.

Long-Term Architectural Shifts Target Memory Safety

Beyond immediate patching, Google focuses on structural changes to eliminate entire categories of bugs

2

. The company is migrating portions of C++ code to Rust, a memory-safe language that addresses root causes of high-severity browser vulnerabilities

5

. Turner suggests the AI vulnerability boom may not last indefinitely for mature products like Chrome, as AI models trained on every past security vulnerability and line of code in Chromium's history can identify patterns across the codebase, including in legacy features like printing that attract fewer human eyes

2

. Google estimates its automated triage process—which filters spam, reproduces proof-of-concept exploits, assigns severity ratings, and routes reports to developers—saves hundreds of hours of developer time monthly

4

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved