Google Chrome Fixes 1,072 Security Bugs in June Using AI—More Than Past Two Years Combined

Reviewed byNidhi Govil

12 Sources

Share

Google fixed 1,072 security bugs in Chrome 149 and Chrome 150 using AI-powered tools, exceeding the 1,036 patches from the previous 23 releases over two years. The company is now piloting twice-a-week security updates to stay ahead of AI-powered cyberattacks as vulnerability discovery accelerates exponentially.

AI Transforms Chrome's Security Patching at Unprecedented Scale

Google has fixed 1,072 security bugs across Chrome 149 and Chrome 150, both released in June, using AI-driven vulnerability discovery tools. This figure surpasses the 1,036 security bugs patched across the previous 23 Chrome releases spanning two years

1

. The exponential increase marks a turning point in how AI is reshaping cybersecurity, with large language models like Gemini now integrated throughout Google's vulnerability management process

5

.

Source: TelecomTalk

Source: TelecomTalk

Doug Turner, Chrome's director of engineering, stated that LLMs have "fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation"

1

. Google now uses AI across the entire workflow—from discovering flaws and reproducing reports to determining severity, generating candidate patches, and creating tests

5

.

How AI Bug Hunting Accelerated Chrome's Vulnerability Discovery

Google's AI-powered approach builds on over a decade of machine learning work in security fuzz testing, dating back to 2012

2

. However, 2026 represents what Parisa Tabriz, Chrome's vice president and general manager, calls "an inflection point both for offense and defense"

2

.

The company developed specialized systems including Naptime, created with Project Zero, which provided AI models with vulnerability research tools. Google later collaborated with DeepMind on Big Sleep, an AI agent that discovered flaws in Chrome's V8 JavaScript engine

5

. One AI-discovered vulnerability was a Chrome sandbox escape that had existed in the codebase for over 13 years

5

.

Turner explained that AI models are trained with encyclopedic knowledge: "Every CVE, every bug the model knows about. And every line of code in Chromium's history, it knows the reason why that line was changed"

2

. This context allows AI to identify weaknesses across Chrome's massive codebase, including legacy features like printing that receive less human attention.

Twice-a-Week Patching Pilots to Counter AI-Powered Cyberattacks

Google Chrome is piloting a twice-a-week security patch cadence to address the reality that AI is finding bugs faster than humans can process them

2

. The browser already moved toward bi-weekly major releases with weekly security updates, but the volume of discoveries necessitated further acceleration

4

.

Source: BleepingComputer

Source: BleepingComputer

"In the face of fast-moving, AI-powered attacks, our delivery cadence must accelerate even further," Google stated in its white paper

4

. The urgency stems from a critical vulnerability: when Google publicly patches a flaw, attackers can reverse-engineer the issue before fixes reach users' machines. Since committed fixes typically take weeks to reach Chrome's stable channel, minimizing this "patch gap" has become essential

4

.

Industry-Wide Impact Shows AI's Dual-Edged Effect on Cybersecurity

Google isn't alone in experiencing this surge. Microsoft patched a record 570 security flaws in its July 2026 Patch Tuesday, citing its own AI usage to explain the jump

1

. By March 2026, Google had received more security bug reports through its Chrome Vulnerability Reward Program than during all of 2025, prompting modifications to prioritize reports that add value beyond automated findings

5

.

Source: Wired

Source: Wired

Dan Lorenc, CEO of security company Chainguard, noted that AI is "finding vulnerabilities in the software they write and the software they use at a pace that is far exceeding defenders' ability to patch and get updates"

3

. The challenge extends beyond developers to system administrators, CISOs, and end users struggling to keep pace with continuous patching

3

.

Dynamic Patching and Structural Security Improvements on the Horizon

To reduce disruption from frequent updates, Google is developing dynamic patching technology that would apply security fixes without requiring browser restarts

4

. Starting with Chrome 150 on macOS, the browser can automatically restart to apply pending updates when running in the background without open windows

5

.

Beyond immediate patching, Chrome's security team is focused on structural changes, including rewriting portions of C++ code in Rust, a memory-safe programming language that eliminates entire categories of common software vulnerabilities

2

. Google's automated vulnerability triage systems now filter spam, reproduce proof-of-concept exploits, assign severity ratings, and route reports to developers, saving hundreds of hours monthly

5

. In May alone, these systems prevented over 20 vulnerabilities from reaching production

5

.

Tabriz and Turner suggest the current spike may eventually plateau as AI exhausts discoverable bugs in mature software like Chrome, creating a new equilibrium

2

. However, the immediate reality is clear: AI's impact on cybersecurity has created both unprecedented defensive capabilities and an overwhelming volume of work that demands fundamental changes to how software security operates across the industry.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved