Google has revealed that artificial intelligence has played a major role in identifying a record number of Chrome browser vulnerabilities this year, significantly increasing the pace of security improvements across its web browser. According to the company, the sharp rise in reported Chrome vulnerabilities since April is the result of deploying AI powered tools capable of identifying security flaws more efficiently than traditional methods. Chrome releases 149 and 150 alone addressed 1,072 security defects, bringing the total number of vulnerabilities patched in 2026 to more than 1,800. The latest Chrome release included 370 security fixes, marking one of the largest security updates for the browser. Google explained that the increased volume of discovered vulnerabilities reflects improvements in detection capabilities rather than a decline in browser security, with AI enabling engineers to uncover issues that had remained hidden within Chrome codebase for years.
One of the most notable discoveries made using Google AI powered security tools was a critical sandbox escape vulnerability tracked as CVE 2026 3545, which had remained undetected in Chrome for approximately 13 years before being patched in Chrome 145 earlier this year. The vulnerability received a CVSS severity score of 9.8 and was described as insufficient data validation within Chrome Navigation component. According to Google, a specially crafted HTML page could have exploited the flaw, allowing a compromised renderer process to trick the browser into reading local files through a sandbox escape. The company stated that its Chrome Security team began experimenting with large language models in 2023, but a dedicated AI agent harness introduced in early 2026 significantly improved vulnerability discovery. The system supports multiple AI models, has been trained using Chrome complete Git history together with previously reported Common Vulnerabilities and Exposures records, incorporates developer supplied SECURITY.md documentation through a critic agent, and repeatedly analyzes the codebase to identify potential weaknesses. Google also emphasized that strict safeguards are built into the platform, with AI analyzing source code only on isolated systems without general internet connectivity.
Beyond identifying vulnerabilities, Google is increasingly relying on artificial intelligence throughout the security development process. The company explained that AI now assists with validating discovered bugs, prioritizing security reports, and generating candidate patches for most identified vulnerabilities. According to Google, this has significantly increased the rate at which Chrome security fixes are produced. AI is also being used earlier in the software development lifecycle to detect vulnerabilities before code is submitted, helping engineers address security issues before they become part of production builds. While these AI capabilities have accelerated security improvements, Google continues to depend on its existing security testing infrastructure and encourages independent security researchers to submit vulnerability reports through its Vulnerability Reward Program. The company noted that combining automated AI analysis with external research continues to strengthen Chrome security while improving the efficiency of vulnerability management across its development process.
Google is also introducing several long term initiatives intended to reduce the time between vulnerability discovery and user protection. The company is testing a twice weekly Chrome security release schedule to complement its existing two week major release cycle while also automating the creation of release notes and Common Vulnerabilities and Exposures descriptions to reduce manual delays. Additional improvements include dynamic patching that allows updates without requiring browser restarts, seamless session restoration, and background restart capabilities that minimize user disruption. At the same time, Google continues working to eliminate entire categories of vulnerabilities by strengthening runtime protections, expanding technologies such as MiraclePtr and MiracleObject, improving memory allocation protections, and reducing out of bounds weaknesses through spanification efforts. The company is also accelerating its transition from C++ to memory safe programming languages such as Rust by building a centralized Rust software development kit, replacing vulnerable code segments, and developing new modular browser components in Rust. Google added that it is also exploring the use of HTML, CSS, and TypeScript for Chrome top level user interface while expanding automated vulnerability scanning and update pipelines for third party software dependencies to strengthen browser security across the entire ecosystem.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.