Chrome Security Bugs Fixed by Google AI in Chrome 149 and 150

Google AI fixes Chrome security bugs in Chrome browser updates

Google has revealed that artificial intelligence helped identify and fix 1,072 Chrome security bugs across the latest Chrome 149 and Chrome 150 releases. The number of vulnerabilities resolved is higher than the combined total addressed in the previous 23 Chrome updates, highlighting how AI is transforming browser security.

_x000D_

The company says its growing use of artificial intelligence has significantly accelerated the process of detecting, analyzing and repairing security flaws before they can be exploited by attackers.

_x000D_ _x000D_

AI Speeds Up Chrome Security Bugs Detection

_x000D_

Google has integrated advanced large language models into its vulnerability management system to improve how Chrome security bugs are discovered.

_x000D_

The company introduced an AI-powered security agent called Big Sleep, developed with Google DeepMind and Project Zero. Google also deployed a Gemini-powered agent that continuously scans Chrome’s codebase for potential vulnerabilities.

_x000D_

These AI tools automatically identify flaws, reproduce bug reports, assign severity levels and even generate possible code fixes, reducing the amount of manual work required from engineers.

_x000D_ _x000D_

AI Finds Critical Vulnerability Hidden for 13 Years

_x000D_

Google said the AI systems have already delivered impressive results.

_x000D_

In one notable case, the automated tools discovered a critical sandbox escape vulnerability that had remained hidden inside the Chrome codebase for more than 13 years.

_x000D_

The company also reported that AI now handles much of the initial bug triage process, saving developers hundreds of hours every month.

_x000D_

During May alone, Google’s internal AI agents prevented more than 20 vulnerabilities from reaching production versions of Chrome.

_x000D_ _x000D_

Faster Updates to Protect Chrome Users

_x000D_

While AI helps identify Chrome security bugs more quickly, Google says faster detection also creates new challenges.

_x000D_

Once security patches become public, attackers often attempt to reverse-engineer the fixes to discover vulnerabilities before users install updates.

_x000D_

To reduce that risk, Google plans to move Chrome to a biweekly major release schedule while also testing security updates twice every week.

_x000D_

The goal is to shorten the time between discovering vulnerabilities and delivering fixes to users worldwide.

_x000D_ _x000D_

Dynamic Patching Improves User Experience

_x000D_

Google is also introducing a new feature called dynamic patching to make security updates less disruptive.

_x000D_

Starting with Chrome 150 on macOS, the browser can automatically restart in the background whenever no browser windows are open, allowing pending updates to install without interrupting users.

_x000D_

The company believes this approach will improve security while making updates virtually invisible during normal browsing.

_x000D_ _x000D_

Google’s Long-Term Browser Security Strategy

_x000D_

Google says artificial intelligence will continue playing a central role in protecting Chrome users.

_x000D_

The company’s long-term strategy focuses on continuous browser security through automated vulnerability detection, recurring updates, background patch installation and improved session restoration.

_x000D_

As cyber threats continue evolving, Google believes AI-powered security tools will become increasingly important in identifying vulnerabilities before attackers can exploit them.

Must Read

Related News