Google is investing in "dynamic matching" to eliminate the need for a full browser restart for most Chrome updates. This feature works by replacing background child processes, such as the Renderer and GPU, with updated binaries on the fly, leveraging Chrome’s multi-process architecture. This development aims to reduce the "patch gap," the time users spend waiting to restart Chrome after an update, which can contribute to N-day exploitation risk.
The Chrome team is actively researching and developing this feature and exploring ways to ensure seamless session restoration, even in complex cases, by saving more state locally. This will become more critical as Chrome moves to a two-week update cycle later this year. In the interim, Google is looking for opportune moments to automatically restart the browser when a seamless session restore can be guaranteed, such as in Chrome 150 for Mac, which will restart when there's a pending update and no open user windows.
Google's expanded use of AI, including large language models (LLMs), has significantly increased the number of security vulnerabilities found and fixed in Chrome. Chrome 149 and 150, both released in June, collectively fixed 1,072 security bugs. This number exceeds the total fixes across the previous 23 Chrome milestones combined, which amounted to 1,036 fixes over the past two years.
The company began using LLMs to improve security fuzzing in 2023 and later collaborated on projects like Naptime and Big Sleep, AI-powered vulnerability discovery agents. In early 2026, Google created a Gemini-powered agent harness to search the broader Chrome codebase for vulnerabilities, reducing false positives and saving weeks of developer time.
Among the vulnerabilities discovered by Google's AI tools was a 13-year-old sandbox escape flaw, tracked as CVE-2026-3545 (CVSS score of 9.8). This issue, patched in Chrome 145 in early May, could have allowed a compromised renderer to trick the browser into reading local files through insufficient data validation in Navigation. The discovery of such a long-standing bug validates the effectiveness of AI-powered vulnerability detection.
With the vastly higher rate of vulnerability identification, Google is concerned that malicious actors will also be able to find software flaws faster. To counter this, Google is considering increasing Chrome's update frequency, potentially introducing two weekly security updates. This aims to deploy patches more rapidly and ensure browsers remain secure against fast-moving, AI-powered attacks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google's Chrome security team used AI agents to discover and patch 1,072 security vulnerabilities in Chrome over two months, exceeding the total fixes from the previous 23 milestones combined. This development demonstrates AI's potential to significantly accelerate vulnerability discovery and remediation in complex software, impacting the security posture of widely used applications.
Google confirmed that its AI-powered agent harness, leveraging Gemini, has significantly increased the detection and patching of Chrome vulnerabilities, leading to over 1,800 fixes this year. This AI system notably uncovered a 13-year-old sandbox escape flaw, CVE-2026-3545, demonstrating its effectiveness in identifying long-standing security issues.
Google's Chrome Security team fixed more bugs in June than in the previous two years combined, crediting the increase to advanced AI models like Gemini for vulnerability discovery. This development signifies a shift in software security, as AI-powered tools are now finding and remediating security flaws at an accelerated rate.
Google plans to increase Chrome's update frequency, potentially to twice per week, in response to a significant rise in AI-detected security flaws. This change aims to deploy patches faster and ensure browsers remain secure against AI-fueled attacks.
Google announced it patched 1,072 security bugs in Chrome during June, exceeding the 1,036 fixes made in the prior two years, attributing this increase to its internal AI tools. This development indicates AI's growing role in vulnerability discovery and patching, impacting cybersecurity strategies for large software providers.
Google reports that its expanded use of AI, including large language models, enabled Chrome to fix 1,072 security bugs across Chrome 149 and 150, a number exceeding fixes from the previous 23 milestones. This development indicates a significant shift in how major software vendors can identify and address vulnerabilities, potentially leading to more secure products.
Google is developing "dynamic matching" to update Chrome without requiring a full browser restart, aiming to close the "patch gap" and improve security. Additionally, Google has been using LLMs since 2023 to find vulnerabilities in the Chrome codebase, leading to the discovery of a 13-year-old bug.
Google is developing "dynamic patching" to allow Chrome updates without requiring a browser restart, aiming to reduce user disruption and mitigate "N-day" attacks. This initiative is part of Google's broader effort to make updates less disruptive as AI-powered tools increase the frequency of bug fixes.