Google says artificial intelligence helped Chrome fix 1,072 security bugs across its two most recent releases, marking a major increase in the browser’s vulnerability detection and patching efforts.
Chrome 149 and Chrome 150 fixed more security bugs than the previous 23 Chrome milestones combined, according to Google. The company now uses large language models throughout its security workflow, from finding flaws to testing possible fixes.
AI expands Chrome security testing
Google started using large language models to improve Chrome security fuzzing in 2023. It later worked with Project Zero on Naptime, a system that gave AI models specialised vulnerability research tools.
The company then partnered with Google DeepMind and Project Zero on Big Sleep. That AI-powered vulnerability discovery agent found security flaws in Chrome’s V8 JavaScript engine and graphics components.
In early 2026, Google developed a Gemini-powered agent harness to scan the wider Chrome codebase. The system was designed to find vulnerabilities while reducing false positives.
One issue found by the system was a Chrome sandbox escape that had existed in the codebase for more than 13 years. If exploited, it could have allowed a compromised renderer to escape Chrome’s sandbox and access local files.
AI agents help analyse and fix vulnerabilities
Google now uses AI across the vulnerability management process. Its systems can help discover bugs, reproduce reports, assess severity, assign issues to developers, generate candidate patches and create security tests.
The company is also encouraging developers to add SECURITY.md files to their projects. These documents outline trust boundaries and threat models, giving AI systems more context when analysing potentially risky code.
Google stressed that multi-agent AI workflows support existing security methods rather than replace them. Fuzzing, for example, remains an important tool for finding complex vulnerabilities.
Chrome receives more vulnerability reports
Google has also seen a sharp rise in submissions through the Chrome Vulnerability Reward Program. By March 2026, it had received more security reports than during all of 2025.
As a result, the company changed the programme to prioritise reports that add value beyond its existing automated security tooling.
AI is also helping Google automate vulnerability triage. The tools can filter spam and duplicate reports, reproduce proof-of-concept exploits, assign severity ratings and route confirmed issues to the appropriate developers.
Google estimates that automation saves developers hundreds of hours each month.
Once a vulnerability is confirmed, AI agents can generate several possible patches. Another agent then evaluates the suggestions and produces supporting information for developers to review.
Google said these systems stopped more than 20 vulnerabilities from reaching production in May, including one critical issue.
Google aims to reduce Chrome’s patch gap
Finding bugs faster only helps if security updates reach users quickly. Google noted that attackers can inspect Chrome’s public source code after a fix is committed and try to reverse-engineer the vulnerability before the patch reaches users.
To reduce that window, Chrome is moving to a two-week major release cycle with weekly security updates. Google is also testing two security releases per week.
The company is developing dynamic patching to let Chrome apply updates without requiring a browser restart. Starting with Chrome 150 on macOS, the browser can automatically restart in the background to install a pending update when no windows are open.
Google’s long-term goal is to keep Chrome continuously updated through dynamic patching, automatic restarts during inactive periods and improved session restoration.
Meta description: Google says AI helped Chrome fix 1,072 security bugs across two releases as it expands automated vulnerability discovery and patching.


0 responses to “Google Says AI Helped Chrome Fix 1,072 Security Bugs in Two Releases”