Google says AI helped Chrome fix 1,072 security bugs in two releases

Google’s AI-Powered Chrome Updates Fix Over 1,000 Security Bugs in Record Time

In a significant breakthrough for browser security, Google has revealed that its use of artificial intelligence has led to an unprecedented number of security vulnerabilities being patched in just two releases of the Chrome browser. A staggering 1,072 bugs were fixed across the latest Chrome 149 and 150 milestones, surpassing the total number of fixes made in the previous 23 Chrome updates combined.

According to Google, its AI-powered systems have become an integral part of the vulnerability management process. The company uses large language models (LLMs) throughout various stages of security testing, including discovering flaws, reproducing reports, determining severity, and assigning bugs to developers. This integration has led to a significant increase in the number of vulnerabilities being identified and fixed.

One notable example of AI-powered discovery is a Chrome sandbox escape that had remained undetected for over 13 years. If exploited, this flaw would have allowed an attacker to bypass security restrictions and access sensitive local files. Fortunately, Google’s systems were able to detect and patch the issue before it could be used by malicious actors.

Google’s multi-agent AI workflows are designed to augment existing security testing methods, such as fuzzing, rather than replace them entirely. By leveraging AI, the company has been able to improve its vulnerability discovery rate while reducing false positives. As a result, Google has seen a significant increase in reports submitted through the Chrome Vulnerability Reward Program.

In fact, by March 2026, the company had received more security bug reports than during all of 2025. In response, Google modified its program to prioritize reports that add new information and insights beyond what its AI systems can already detect and process.

To further streamline its vulnerability management processes, Google is automating tasks such as filtering spam and duplicates, reproducing proof-of-concept exploits, assigning severity ratings, and routing reports to the relevant developers. This automation has saved hundreds of hours of developer time each month.

However, Google’s efforts to improve security are not without their challenges. As the company transitions to a two-week major release cycle with weekly security updates, it is working to close the gap between patching vulnerabilities and delivering them to users. To address this issue, Google is piloting dynamic patching on macOS, which allows Chrome to apply updates in the background without requiring a restart.

As the threat landscape continues to evolve, Google’s commitment to using AI-powered systems to improve browser security is a step in the right direction. For organizations and individuals alike, it serves as a reminder of the importance of staying vigilant and proactive when it comes to cybersecurity.

To stay ahead of potential threats, it’s essential for users to adopt a comprehensive approach to security testing. This includes regularly updating software, running vulnerability scans, and implementing robust incident response plans. By doing so, organizations can reduce their exposure to cyber attacks and ensure that their systems remain secure in the face of evolving threats.


Source: Bleeping Computer — 2026-07-30