Google said expanded use of AI across Chrome’s security workflow helped it identify and remediate 1,072 security bugs in Chrome 149 and Chrome 150, a total that exceeded the number fixed across the prior 23 Chrome milestones combined. The company said large language models and Gemini-based systems are now being used for vulnerability discovery, reproduction, severity assessment, bug routing, patch generation, test creation, code review, and update delivery. Google also said AI-assisted analysis uncovered a sandbox escape flaw that had existed for more than 13 years and could have allowed a compromised renderer to access local files.
Google attributed the spike in fixes to improved detection rather than a decline in Chrome security, describing AI as a way to scale vulnerability hunting and preemptive remediation across a massive codebase. To shorten the window between patch creation and user protection, the company is piloting twice-weekly security releases and developing dynamic patching and less disruptive automatic restart mechanisms. Google also said it is expanding memory-safety efforts such as MiraclePtr, moving new components to Rust, scanning code changes with AI before merge, and improving third-party component update pipelines.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Google reported that Chrome 149 and Chrome 150, both released in June, contained fixes for 1,072 security bugs. The company said this exceeded the total number of bugs fixed across the prior 23 Chrome milestones combined.
Google said DeepMind and Project Zero tools integrated into Chrome’s continuous integration environment prevented more than 20 vulnerabilities, including one critical issue, from reaching production. The disclosure was presented as a concrete outcome of the company’s expanding AI-assisted security pipeline.
Google patched CVE-2026-3545, a critical Chrome Navigation component sandbox escape flaw with a CVSS score of 9.6 that could allow local file reads. The vulnerability had reportedly existed undetected for more than 13 years before being fixed.
Google said its Big Sleep AI agent, combined with Google Threat Intelligence, discovered the critical SQLite vulnerability CVE-2025-6965 and helped stop its exploitation before it occurred. The company described this as the first known case of an AI agent directly foiling attempts to exploit a vulnerability in the wild.
Google said OSS-Fuzz had been tested with large language models to automatically generate new fuzz targets for open source projects, increasing code coverage by roughly 1.5% to 31% in evaluated cases. The company also said an LLM-generated OpenSSL target rediscovered CVE-2022-3602 in previously uncovered code and planned to open source the evaluation framework.
Google said it enabled BackupRefPtr, the core of its MiraclePtr mitigation against use-after-free exploitation, for Chrome's browser process on Windows and Android in Chrome 102 Stable. The company said it had rewritten more than 15,000 raw pointers and estimated the mitigation could protect roughly half of browser-process use-after-free issues from exploitation.
Google said it is testing a pilot release cadence for Chrome security updates twice per week to respond to faster vulnerability discovery and reduce the delay between patch publication and user protection. The company said the change is motivated in part by increased AI-assisted flaw discovery and rising external bug report volume.
Google said it expanded AI use across Chrome's vulnerability management lifecycle, including flaw discovery, triage, patch generation, code review, and update delivery. It also said it is piloting more frequent security releases and developing faster patch deployment mechanisms.
Google reported that Chrome 151 alone contained 370 security fixes, extending the elevated patching pace it had previously highlighted for Chrome 149 and 150. The disclosure was cited alongside broader claims that Chrome bug fixes in 2026 had exceeded 1,800.
Google said a Gemini-based system uncovered a Chrome sandbox escape vulnerability that had existed for more than 13 years and could have allowed a compromised renderer to access local files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcetechrepublic.com
Open sourcezdnet.com
Open sourcexakep.ru
Open sourceblog.google
Open sourcesecurity.googleblog.com
Open sourcesecurity.googleblog.com
Open sourcenvd.nist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.