Google uses AI to fix over 1,000 Chrome security flaws in record update

Big Sleep and Gemini-powered AI agents help Google detect 1,072 Chrome vulnerabilities, prompting faster security updates and automatic background patching

Google has announced a significant milestone in browser security, revealing that artificial intelligence helped identify and fix 1,072 security vulnerabilities in the latest Chrome 149 and Chrome 150 releases. The number of issues resolved in these two versions exceeds the combined total of vulnerabilities addressed across the previous 23 Chrome updates.

The achievement reflects Google’s growing reliance on AI-powered tools to strengthen browser security and accelerate vulnerability detection.

The dramatic increase in discovered vulnerabilities is largely due to Google’s integration of advanced large language models into Chrome’s security workflow.

The company deployed an AI-powered agent called Big Sleep, developed in partnership with Google DeepMind and Project Zero, alongside a dedicated Gemini-based security agent. These AI systems automate multiple stages of the vulnerability management process, including identifying security flaws, reproducing bug reports, assigning severity levels, and even generating potential code patches.

Google said the automated tools have already demonstrated impressive results. In one notable case, the AI system discovered a critical sandbox escape vulnerability that had remained hidden within Chrome’s codebase for more than 13 years.

The company also reported that AI-powered bug triage is saving developers hundreds of engineering hours every month. During May alone, Google’s internal AI agents prevented more than 20 security vulnerabilities from ever reaching production versions of Chrome.

While AI enables Google to detect security flaws much faster, it also creates a new challenge. Once patches are publicly released, attackers may attempt to reverse-engineer the fixes to exploit users who have not yet updated their browsers.

To reduce this security window, Google is moving Chrome to a biweekly major release schedule while also testing security updates twice each week to keep pace with the growing number of AI-discovered vulnerabilities.

To minimise disruptions caused by more frequent updates, Google is introducing a dynamic patching feature. Starting with Chrome 150 on macOS, the browser can automatically restart in the background when no Chrome windows are open, allowing security updates to be installed without interrupting users.

Google said its long-term vision is to maintain continuous browser protection through recurring security updates, automatic background restarts, and improved session restoration, ensuring users remain protected against emerging cyber threats with minimal disruption.