Google's AI patched more Chrome bugs in two releases than it had in two years.

Google's AI patched more Chrome bugs in two releases than it had in two years.

Artificial Intelligence
Google's AI patched more Chrome bugs in two releases than it had in two years, including a 13-year-old flaw
Google is piloting two Chrome security releases per week and developing updates that install without requiring a browser restart for faster patched.

Google has published a white paper detailing how AI is transforming Chrome's security pipeline. Chrome versions 149 and 150, both released in June, collectively fixed 1,072 security bugs. That figure exceeds the total number of bugs patched across the previous 23 Chrome versions combined, dating back to June 2024.

Google has been building a multi-agent AI workflow for vulnerability research since 2023. Today, its AI-powered agents are scanning code at a scale and speed that were not previously possible. In one case, this AI-driven analysis uncovered a Chrome sandbox escape vulnerability that had remained hidden in the codebase for more than 13 years. If exploited, it could have allowed attackers to escape Chrome's sandbox and access local files.


The pace of discovery is now fast enough that Google is rethinking its entire update delivery model. Chrome moved to a two-week major release cycle earlier this year, but the company is now piloting a shift to two security releases per week for targeted patches. In other words, Google wants to reduce the time between identifying a vulnerability and getting a fix into users' hands, giving attackers less time to reverse-engineer vulnerabilities and develop exploits.

Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed
The company is also working on several approaches to make Chrome updates faster and eliminate the need for a restart, a step many users delay and one that can leave their systems exposed longer than intended. Chrome 150 on macOS introduced what Google calls a "zero window restart," which takes advantage of the way macOS apps continue running in the background after all windows are closed.



Another solution is dynamic patching, which would allow Chrome to apply security updates without requiring a restart by replacing background processes with updated binaries on-the-fly. Google has not provided a timeline for when dynamic patching will arrive in stable builds, but describes it as an active area of investment. 

Previous post

Napište komentář