Google has shifted Chrome desktop and mobile releases from a four-week to a two-week cadence, shortening the time between public Chromium fixes and their availability to users. The company cited faster vulnerability discovery, exploit development, and spearphishing enabled by advanced and agentic AI, and said it is testing delivery of two security updates per week. Google is also developing dynamic patching intended to reduce or eliminate browser-restart requirements.
Organizations using Chrome Enterprise's Extended Stable channel will continue to receive major releases every eight weeks, but critical security fixes will be backported and deployed weekly. Security teams should verify that managed Chrome fleets can receive interim security updates promptly and reassess patch-compliance monitoring as Chrome's release cadence increases.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Google disclosed that it is developing an early-stage dynamic-patching capability intended to reduce or eliminate the need for users to fully restart Chrome after updates. While it is under development, Google is optimizing background restarts and session restoration.
Google said it is testing a cadence of two Chrome security updates per week as part of its effort to shorten exposure to publicly visible Chromium vulnerabilities.
Google changed Chrome desktop and mobile releases from a four-week cadence to a two-week cadence, reducing the maximum standard interval from a public Chromium fix to user availability from 28 days to 14 days. Google said the security-driven change addresses the faster discovery and exploitation of vulnerabilities, including risks accelerated by AI.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.