How AI Turned Chrome’s Security Team Into Bug-Finding Machines

How AI Turned Chrome’s Security Team Into Bug-Finding Machines

Google just dropped a number that sounds almost unbelievable: in two Chrome releases last month, the company fixed 1,072 security bugs. That’s more than the previous 23 Chrome versions combined. And they did it in one month.

The secret? AI. And not just any AI — Gemini-powered agents that are now hunting vulnerabilities, triaging reports, and even writing patches faster than human teams ever could.

What Actually Changed

Chrome’s security team has been using machine learning for years — fuzzing, automated testing, the usual stuff. But early 2026 marked a turning point. They built what they call an “agent harness” that uses Gemini to scan the entire Chrome codebase for vulnerabilities.

The results were immediate. The AI found a sandbox escape bug that had been hiding in the code for over 13 years. A bug that survived longer than most Chrome engineers have worked at the company. That moment, according to the team, “cemented the potential of AI-powered vulnerability detection”.

But finding bugs is only half the story.

From Discovery to Patch — All Automated

The AI doesn’t just surface issues. It handles the entire pipeline:
  • Filters spam and duplicate reports — tasks that used to take 5–30 minutes per report
  • Tries to reproduce the vulnerability
  • Labels severity levels
  • Assigns issues to the right teams
  • Generates candidate patches
  • Reviews those patches with a separate “critic” agent
  • Writes tests to verify the fix works across all platforms
Google says this workflow saves hundreds of engineering hours per month. That’s not a small number when you’re dealing with thousands of bugs.

The New Normal: Twice-Weekly Patches

Here’s the catch: finding more bugs means pushing more updates. Chrome is now piloting security releases twice a week. For context, a decade ago Chrome pioneered automatic updates when everyone else was doing patches every six weeks.

“Will that last forever? Who knows,” Doug Turner, Chrome’s director of engineering, told WIRED. But for now, the team is prioritizing speed over convenience.

And they’re working on making updates less disruptive too — testing “dynamic patching” that wouldn’t require a full browser restart.

The Bigger Picture

This isn’t just a Google story. Microsoft patched a record 570 vulnerabilities in July and also credited AI. The security industry is experiencing what Turner calls a “fundamental shift in the economics of cybersecurity” — vulnerability discovery has become an automated, industrial-scale operation.

Parisa Tabriz, Chrome’s VP and GM, put it simply: “It really feels like an inflection point both for offense and defense”.

The AI bug-hunting arms race is real. And for now, at least, the defenders are winning — one patch at a time.

Post a Comment

Previous Post Next Post