Categorie: News

Google: AI fixed 1,072 security bugs in just two updates

In a recent announcement, Google has announced how the use of artificial intelligence is significantly increasing the company’s ability to identify and resolve vulnerabilities within its browser Chrome.

This has led to the fixing of over 1,000 security bugs over the course of the last two major updates, outlining an increasingly extensive integration of AI into corporate procedures.

Google Chrome, over 1,000 security issues fixed with AI

Credits: Google

Specifically, the releases of Chrome 149 and 150 have involved the resolution of 1,072 issues, a volume greater than the sum of the bugs fixed during the previous 23 updates of the browser.

Currently, the Mountain View company is making extensive use of LLMs in all stages of vulnerability management. This integration covers the discovery of defects, the reproduction of reports, the assessment of severity, the assignment of tasks to developers, the creation of preliminary patches, and the drafting of tests.

The path to this result began in 2023, when Google introduced the use of language models to optimize the security fuzzing. Subsequently, in collaboration with Project Zero, Naptime was born, a system designed to provide AI-based tools with the specific resources needed for vulnerability research.

This work was then continued with the contribution of Google DeepMind, leading to the creation of Big Sleep, an agent capable of identifying vulnerabilities within the JavaScript V8 engine and the graphical components of Chrome.

Discoveries and multi-agent systems

Earlier this year, Google structured a Gemini-guided system, designed to analyze Chrome’s code extensively and limit false positives. Among the successes of this system is the discovery of a sandbox-escape vulnerability latent in the source code for over 13 years.

This defect, if exploited, would have allowed a compromised renderer to evade the sandbox and mislead the browser, gaining access to local files.

At the same time, Google is inviting its developers to include files SECURITY.md to delineate reliability boundaries and threat models. This practice helps AI systems recognize security implications of operations.

Workflows based on multi-agent systems are designed to assist, not replace traditional security testing methods, including fuzzing, which continues to prove effective in uncovering advanced vulnerabilities.

Increase in reports and automation

The company has observed a sharp rise in reports submitted through the Chrome Vulnerability Reward Program. By March 2026, the number of security vulnerability reports had already surpassed the total for all of 2025.

This surge has prompted Google to modify the program, giving priority to reports that enrich the information already collected and analyzed through automated tools.

Automation also extends to the vulnerability classification process. This includes spam and duplicate filtering, the reproduction of exploit proof-of-concepts, the assignment of severity levels, and routing reports to competent developers.

According to the company’s estimates, this automated procedure saves hundreds of developer hours each month.

Patch development and deployment speed

Once a vulnerability is verified, specific agents generate several patch proposals, while another agent evaluates the solutions and prepares detailed information for review by the developers. By May, the intervention of these systems blocked more than 20 vulnerabilities, including one at a critical level, before they reached the production environment.

However, Google notes that greater speed in identifying and resolving flaws also requires greater speed in distributing updates to users.

Indeed, as soon as a fix is inserted into Chrome’s public source code, attackers can examine the change and attempt to reverse-engineer the vulnerability before the update reaches users’ devices.

To reduce this time window, Chrome is moving to a biweekly major release cycle, accompanied by weekly security updates, and is testing two security releases per week.

To minimize user disruption, Google is working on the “dynamic patching“, a technology designed to allow updates to be installed without requiring a browser restart. Furthermore, starting with version 150 on macOS, Chrome can automatically restart to apply a pending update when running in the background without active windows.

The company’s ultimate goal is to keep the browser constantly updated through dynamic patching, automatic restarts during idle times, and improvements to session restoration.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

AliExpress August Sale: Up to 60% Off and New Coupons to Redeem!

New month and new opportunities from AliExpress: August kicks off with insider access to the…

10 hours ago

Xiaomi 18 Pro Max Global-certified: are there hopes for Italy?

There have been rumors for days about the debut of the Xiaomi 18 Pro in…

11 hours ago

What will the Samsung Galaxy S26 FE cameras be like? The first confirmations arrive

The Samsung Galaxy S26 FE is preparing to close the year of launches for the…

13 hours ago

Honor confirms the MagicOS 11 presentation date: event in August and more Liquid Glass

While all eyes are fixed on Robot Phone and on its technological novelties (with an…

13 hours ago

Redmi Note 17 Pro Max: the European label confirms the massive battery

The European launch of the Redmi Note 17 series seems to be turning into no…

14 hours ago

A full-screen, bezel-less smartphone? Tecno reveals its experiment

The brand Tecno has announced its new concept phone, but this time it's not a…

15 hours ago