Google Says AI Helped Chrome Fix 1,072 Security Bugs


chrome vulnerabilities
Image credit: Google

Google says AI helped Chrome fix 1,072 security bugs across Chrome 149 and Chrome 150, exceeding the total fixed during the previous 23 releases combined.

Google now uses large language models across nearly every stage of Chrome’s vulnerability management process.

Google uses AI throughout Chrome security testing

Google’s AI systems help security teams find vulnerabilities, reproduce bug reports, and assess severity. They also route issues to the right teams, suggest patches, and generate tests to validate fixes, while filtering spam, duplicates, and low-quality reports, thus saving engineers hundreds of hours each month.

Since 2023, Google has integrated large language models into its fuzzing systems, which test software with unexpected or malformed inputs to find crashes. The company says AI supports rather than replaces fuzzing, which remains important for uncovering complex vulnerabilities.

Security files give AI tools more context

Google is encouraging Chrome developers to add SECURITY.md files to their projects.

These documents describe trust boundaries, threat models, sensitive operations, and other security assumptions. This additional context helps AI systems distinguish dangerous behavior from legitimate browser activity.

Google wants developers to provide security context alongside the code so automated tools can produce more accurate findings and reduce false positives.

Multiple AI agents can review competing fixes

Google is also testing multi-agent workflows where several AI agents analyze the same vulnerability.

One agent can generate a patch while another reviews it for security, compatibility issues, or incomplete fixes, while others suggest alternative solutions.

In May, these systems reportedly prevented over 20 vulnerabilities from reaching production, including one critical flaw.

Developers still review and approve all fixes, with Google positioning the agents as support tools rather than replacements for human engineers or existing security processes.

Chrome bug reports are increasing rapidly

Chrome’s Vulnerability Reward Program has seen a sharp rise in submissions, with Google receiving more reports by March 2026 than in all of 2025.

AI-assisted research may surface many of the same issues as internal systems, so Google is adjusting rewards to prioritize reports that add unique value, such as new attack techniques, missed flaws, or deeper impact analysis.

Google wants to reduce Chrome’s patch gap

Faster vulnerability discovery is pushing Google to speed up Chrome security updates.

When a patch is published, attackers can often reverse-engineer it to find the underlying flaw, leaving users exposed until they install the update and restart the browser. This creates a “patch gap” where exploits can emerge before fixes are widely applied.

To address this, Google is testing twice-weekly Chrome security releases and developing dynamic patching that can apply some updates without a restart. Together, these changes aim to reduce the time between a fix and user protection while minimizing disruption.

AI security tools are finding more vulnerabilities

Other technology companies are also using AI agents to detect software flaws, although finding bugs faster does not guarantee that engineering teams can fix them immediately.

Microsoft reportedly can’t address all the bugs found by Anthropic’s Claude Mythos, highlighting how AI security systems can surface vulnerabilities faster than companies can investigate and patch them.

While Mythos is useful in discovering vulnerabilities, a recent incident shows AI agents can also introduce new security risks when testing environments are not properly restricted, as seen when Anthropic said Claude hacked three organizations and published malicious PyPI code during internal security testing.

Meanwhile, attackers continue to rely on social engineering and remote access tools rather than software vulnerabilities alone. In a separate campaign, Microsoft Teams IT support scams led to Chaos ransomware attacks after threat actors persuaded employees to grant them remote access.

More about the topics: browser, Chrome, Google, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages