News Article · Jul 31, 2026 at 12:11 AM
3 min read 0
Member
Google expands AI role in Chrome security, patches 1,072 bugs across two releases and tests restartless updates
Security #vulnerability #AI #Chrome #security #Google #Rust #patching #dynamic patching #MiraclePtr #Alpha-Omega

Google expands AI role in Chrome security, patches 1,072 bugs across two releases and tests restartless updates

Google says AI helped Chrome fix 1,072 security bugs across versions 149 and 150, more than the previous 23 releases combined. The company is now piloting twice-weekly security updates and developing dynamic patching to eliminate browser restarts.

Google has expanded the use of artificial intelligence across Chrome's security workflow, using AI to find vulnerabilities, triage bug reports, generate patches and review code. The company said the approach helped fix 1,072 security bugs across Chrome 149 and 150, more than the total patched during the previous 23 stable releases combined.

According to Google, the jump in fixed vulnerabilities reflects improved detection rather than a decline in Chrome's security posture. The company noted that an increase in bugs found and fixed is not a sign of failure. External bug reports also rose sharply, with more submissions logged by March 2026 than during all of 2025.

AI agents find a 13-year-old sandbox escape

Google has used AI to support Chrome security for several years, but in 2026 it deployed a Gemini-based system that searches the Chrome codebase for vulnerabilities. One notable finding was a sandbox escape flaw that had remained in the code for more than 13 years. According to Google, the vulnerability could have allowed a compromised renderer process to access local files.

The company has since added support for open-weight and proprietary models working alongside each other and built a knowledge base from Chrome's Git history and previously disclosed CVEs. A separate critic agent reviews SECURITY.md files that developers use to document trust boundaries in code. Vulnerability scans run multiple times because AI model outputs can vary between runs.

  • AI generates candidate patches, reviews proposed fixes and writes tests before engineers review changes.
  • Google is piloting two security releases per week instead of its usual weekly cadence, citing AI's ability to help attackers analyze vulnerabilities more quickly.
  • The company is investing in dynamic patching that would allow Chrome to update key browser components without a complete restart.
  • Google is testing ways to restart the browser automatically when users are less likely to be disrupted.
  • Chrome depends on more than 2,300 third-party components, and Google is moving them to pipelines that update them automatically.

Closing the patch gap with dynamic updates

Google is working to reduce the patch gap, the period between publishing a security fix in Chrome's source code and users installing the update. During that window, attackers can analyze publicly available patches to develop exploits before updates reach users. Even with a faster release cadence, proper public disclosure remains paramount, the company noted.

To shorten the window between releasing and applying security updates, Google is developing dynamic patching that would allow Chrome to update key browser components without a complete restart. The company acknowledged that users have understandable reasons to delay restarting Chrome, as a restart can be disruptive and requires scheduling between tasks. Longer term, Google is removing entire categories of bugs from Chrome's C++ code by expanding a memory-safety tool called MiraclePtr and migrating new components to the memory-safe language Rust. The company is also contributing $12.5 million to the Alpha-Omega project, which supports open-source maintainers.

Fact check

  • Chrome 149 and 150 fixed 1,072 security bugs, exceeding the total fixed during the previous 23 stable releases combined.

    verified · source

  • A Gemini-based AI system found a sandbox escape vulnerability that had been in Chrome's code for more than 13 years.

    verified · source

  • Google is piloting two security releases per week instead of its usual weekly cadence.

    verified · source

  • Google is developing dynamic patching to allow Chrome to update key components without a full restart.

    verified · source

  • Google is contributing $12.5 million to the Alpha-Omega project.

    verified · source

Source reporting (5)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 67 users online: 0 registered, 61 guests and 6 bots.

Most users ever online was 9,867 on 30 Jul 2026, 2:30 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 373