Google expands AI role in Chrome security, patches 1,072 bugs across two releases and tests restartless updates
Google says AI helped Chrome fix 1,072 security bugs across versions 149 and 150, more than the previous 23 releases combined. The company is now piloting twice-weekly security updates and developing dynamic patching to eliminate browser restarts.
Google has expanded the use of artificial intelligence across Chrome's security workflow, using AI to find vulnerabilities, triage bug reports, generate patches and review code. The company said the approach helped fix 1,072 security bugs across Chrome 149 and 150, more than the total patched during the previous 23 stable releases combined.
According to Google, the jump in fixed vulnerabilities reflects improved detection rather than a decline in Chrome's security posture. The company noted that an increase in bugs found and fixed is not a sign of failure. External bug reports also rose sharply, with more submissions logged by March 2026 than during all of 2025.
AI agents find a 13-year-old sandbox escape
Google has used AI to support Chrome security for several years, but in 2026 it deployed a Gemini-based system that searches the Chrome codebase for vulnerabilities. One notable finding was a sandbox escape flaw that had remained in the code for more than 13 years. According to Google, the vulnerability could have allowed a compromised renderer process to access local files.
The company has since added support for open-weight and proprietary models working alongside each other and built a knowledge base from Chrome's Git history and previously disclosed CVEs. A separate critic agent reviews SECURITY.md files that developers use to document trust boundaries in code. Vulnerability scans run multiple times because AI model outputs can vary between runs.
- AI generates candidate patches, reviews proposed fixes and writes tests before engineers review changes.
- Google is piloting two security releases per week instead of its usual weekly cadence, citing AI's ability to help attackers analyze vulnerabilities more quickly.
- The company is investing in dynamic patching that would allow Chrome to update key browser components without a complete restart.
- Google is testing ways to restart the browser automatically when users are less likely to be disrupted.
- Chrome depends on more than 2,300 third-party components, and Google is moving them to pipelines that update them automatically.
Closing the patch gap with dynamic updates
Google is working to reduce the patch gap, the period between publishing a security fix in Chrome's source code and users installing the update. During that window, attackers can analyze publicly available patches to develop exploits before updates reach users. Even with a faster release cadence, proper public disclosure remains paramount, the company noted.
To shorten the window between releasing and applying security updates, Google is developing dynamic patching that would allow Chrome to update key browser components without a complete restart. The company acknowledged that users have understandable reasons to delay restarting Chrome, as a restart can be disruptive and requires scheduling between tasks. Longer term, Google is removing entire categories of bugs from Chrome's C++ code by expanding a memory-safety tool called MiraclePtr and migrating new components to the memory-safe language Rust. The company is also contributing $12.5 million to the Alpha-Omega project, which supports open-source maintainers.
Fact check
-
Chrome 149 and 150 fixed 1,072 security bugs, exceeding the total fixed during the previous 23 stable releases combined.
verified · source
-
A Gemini-based AI system found a sandbox escape vulnerability that had been in Chrome's code for more than 13 years.
verified · source
-
Google is piloting two security releases per week instead of its usual weekly cadence.
verified · source
-
Google is developing dynamic patching to allow Chrome to update key components without a full restart.
verified · source
-
Google is contributing $12.5 million to the Alpha-Omega project.
verified · source
Source reporting (5)
- Help Net Security · AI takes on a bigger role in finding Chrome vulnerabilities
- BleepingComputer · Google says AI helped Chrome fix 1,072 security bugs in two releases
- WIRED · Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
- 9to5Google · Google wants to update Chrome without a full browser restart
- The Verge · Google is working on Chrome updates that don’t require restarts
Join the conversation
You need to be registered and logged in to comment on blog articles.
0 Comments
No comments yet
Be the first to share your thoughts on this article.