In brief: AI-powered systems have massively increased Google’s patch speed and volume while simultaneously aiming to shorten the time between patch completion and user distribution.
Google has closed a total of 1,072 security vulnerabilities in Chrome versions 149 and 150 — more than in the previous 23 versions combined. Language models are employed in practically every step of the vulnerability management process, from vulnerability detection to test creation.
Google now uses language models in practically every stage of security work: in identifying vulnerabilities, reproducing reported errors, assessing severity, assigning tasks to developers, creating patch proposals, and writing associated tests. Since 2023, Google has worked with fuzzing techniques improved through language models. With the security team Project Zero, the system Naptime was developed, and later together with Google DeepMind the AI agent Big Sleep, which found vulnerabilities in the JavaScript engine V8 and graphics components. In early 2026, Google built an agent based on Gemini that systematically scans the entire Chrome codebase for vulnerabilities and aims to reduce false positives.
One of the vulnerabilities discovered this way was a sandbox escape possibility that had existed for over 13 years. Google emphasizes that AI-assisted methods do not replace traditional fuzzing tools but rather complement them. In parallel, the number of reports through the Chrome Vulnerability Reward Program increased significantly: by March 2026, more reports had been received than throughout the entire year 2025. Google adapted the program to specifically prioritize reports that go beyond the automatically discovered vulnerabilities. Pre-screening of incoming reports — spam and duplicate filtering, reproduction of proofs, severity assessment — is now largely automated. According to Google, this saves several hundred developer work hours per month. In May, the systems prevented over 20 vulnerabilities, including a critical one, before their integration into production code.
To leverage the window available to attackers after they analyze published source code changes, Google is working on shortening the timeframe between a completed patch and user distribution. Chrome is transitioning to a two-week major version cycle with weekly security updates and is even testing two security updates per week. Additionally, Google is developing dynamic patching, which will allow updates to be deployed in the future without a browser restart. Since Chrome 150, the browser on macOS can already automatically restart to apply a pending update when running in the background without open windows.
Source: www.it-daily.net · Published 1 August 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.