August 5, 2026

Google AI Supercharges Chrome Security, Fixing 1,072 Bugs

In brief

Google says artificial intelligence has transformed Chrome’s vulnerability-management process, helping the company fix 1,072 security bugs across two recent releases—more than in the previous 23 Chrome milestones combined. An agent system built around Gemini searches the broader codebase with fewer false positives and uncovered, among other flaws, a 13-year-old sandbox escape that could allow a compromised renderer to read local files. AI also automates report triage by identifying duplicates, reproducing bugs, assigning severity and routing cases, saving developers hundreds of hours each month. For remediation, specialized agents generate candidate patches, assess them and create cross-platform tests before human review, while tools developed with DeepMind and Project Zero run daily in Chrome’s continuous-integration system.

Chrome is also addressing the delay between publicly committing a fix and delivering it to users, when attackers may reverse-engineer the vulnerability. Google is developing dynamic patching to update background processes without a full restart, and Chrome 150 can automatically restart on macOS after all windows close when an update is pending. Longer-term defenses include expanding MiraclePtr against use-after-free bugs, enforcing unsafe-buffer warnings across 97% of first-party code and introducing a centralized Rust SDK for rewriting high-risk components. Google is additionally automating updates for Chrome’s more than 2,300 third-party dependencies, while adjusting its vulnerability-reward program to prioritize research beyond weaknesses already detectable by internal AI systems.

Source: Security Affairs

Explore More Insightful Articles: