Categorie: News

Google: AI fixed 1,072 security bugs in just two updates

In a recent announcement, Google has announced how the use of artificial intelligence is significantly increasing the company’s ability to identify and resolve vulnerabilities within its browser Chrome.

This has led to the fixing of over 1,000 security bugs over the course of the last two major updates, outlining an increasingly extensive integration of AI into corporate procedures.

Google Chrome, over 1,000 security issues fixed with AI

Credits: Google

Specifically, the releases of Chrome 149 and 150 have involved the resolution of 1,072 issues, a volume greater than the sum of the bugs fixed during the previous 23 updates of the browser.

Currently, the Mountain View company is making extensive use of LLMs in all stages of vulnerability management. This integration covers the discovery of defects, the reproduction of reports, the assessment of severity, the assignment of tasks to developers, the creation of preliminary patches, and the drafting of tests.

The path to this result began in 2023, when Google introduced the use of language models to optimize the security fuzzing. Subsequently, in collaboration with Project Zero, Naptime was born, a system designed to provide AI-based tools with the specific resources needed for vulnerability research.

This work was then continued with the contribution of Google DeepMind, leading to the creation of Big Sleep, an agent capable of identifying vulnerabilities within the JavaScript V8 engine and the graphical components of Chrome.

Discoveries and multi-agent systems

Earlier this year, Google structured a Gemini-guided system, designed to analyze Chrome’s code extensively and limit false positives. Among the successes of this system is the discovery of a sandbox-escape vulnerability latent in the source code for over 13 years.

This defect, if exploited, would have allowed a compromised renderer to evade the sandbox and mislead the browser, gaining access to local files.

At the same time, Google is inviting its developers to include files SECURITY.md to delineate reliability boundaries and threat models. This practice helps AI systems recognize security implications of operations.

Workflows based on multi-agent systems are designed to assist, not replace traditional security testing methods, including fuzzing, which continues to prove effective in uncovering advanced vulnerabilities.

Increase in reports and automation

The company has observed a sharp rise in reports submitted through the Chrome Vulnerability Reward Program. By March 2026, the number of security vulnerability reports had already surpassed the total for all of 2025.

This surge has prompted Google to modify the program, giving priority to reports that enrich the information already collected and analyzed through automated tools.

Automation also extends to the vulnerability classification process. This includes spam and duplicate filtering, the reproduction of exploit proof-of-concepts, the assignment of severity levels, and routing reports to competent developers.

According to the company’s estimates, this automated procedure saves hundreds of developer hours each month.

Patch development and deployment speed

Once a vulnerability is verified, specific agents generate several patch proposals, while another agent evaluates the solutions and prepares detailed information for review by the developers. By May, the intervention of these systems blocked more than 20 vulnerabilities, including one at a critical level, before they reached the production environment.

However, Google notes that greater speed in identifying and resolving flaws also requires greater speed in distributing updates to users.

Indeed, as soon as a fix is inserted into Chrome’s public source code, attackers can examine the change and attempt to reverse-engineer the vulnerability before the update reaches users’ devices.

To reduce this time window, Chrome is moving to a biweekly major release cycle, accompanied by weekly security updates, and is testing two security releases per week.

To minimize user disruption, Google is working on the “dynamic patching“, a technology designed to allow updates to be installed without requiring a browser restart. Furthermore, starting with version 150 on macOS, Chrome can automatically restart to apply a pending update when running in the background without active windows.

The company’s ultimate goal is to keep the browser constantly updated through dynamic patching, automatic restarts during idle times, and improvements to session restoration.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

OPPO Find X10 Pro Max will be the first with Dimensity 9600 Pro and will launch outside China

OPPO is preparing to expand its international offering by officially announcing the arrival on the…

15 hours ago

MediaTek’s first 2nm chips are official, up to 61% lower power consumption and much more AI capabilities

MediaTek has officially unveiled its new high-end smartphone processors, the Dimensity 9600 Pro and the…

15 hours ago

When are the Googlebooks arriving? Official pre-order date revealed

The Mountain View-based company has officially confirmed that the pre-orders for the new Googlebook will…

22 hours ago

Honor Robot Phone is the most original Camera Phone… but how durable is it?

Honor Robot, officially launched in China in August with its titanium 200 MP gimbal camera,…

2 days ago

One UI 9 transforms Galaxy Z Flip 7’s external display: new home, gestures and widgets

The external panel of Galaxy Z Flip 7 has always been one of the most…

2 days ago

Galaxy S26 could cost more: the memory crisis behind the price hikes

Galaxy S26, Galaxy S26+ and Galaxy S26 Ultra have been on the South Korean market…

2 days ago