live markets
S&P 5006,389.45▲ 0.42%NASDAQ21,102.30▲ 0.61%DOW44,812.10▼ 0.18%GOLD3,412.80▲ 0.35%WTI CRUDE68.42▼ 1.12%BRENT72.18▼ 0.94%EUR/USD1.0842▲ 0.08%GBP/USD1.3391▼ 0.05%JPY/USD0.0068▲ 0.11%NAT GAS3.12▲ 0.74%
pulseofnations.
Sun, Aug 2 2026 — 03:00 UTC telegram ↗ Join the wire

Google AI Fixed 1,072 Chrome Bugs Including 13-Year-Old Flaw

Google says its Gemini-powered AI agent harness fixed 1,072 Chrome security bugs in two releases, uncovering a sandbox escape hidden for over 13 years.

Google announced on Thursday that its new AI-powered security system helped patch 1,072 security vulnerabilities across Chrome 149 and 150, surpassing the total number of bugs fixed in the previous 23 milestones combined. The breakthrough came from an agent harness built on Google’s Gemini AI models that automatically scans the Chrome codebase for vulnerabilities with higher efficiency and fewer false positives than previous automated tools.

The most alarming finding was a critical sandbox escape vulnerability that had quietly survived in Chrome’s codebase for more than 13 years. According to Google’s security blog, the flaw would have allowed a compromised renderer process to trick the browser into reading local files on a user’s machine, a severe breach of Chrome’s multi-layered security architecture. The bug was so deeply embedded that no human auditor had ever flagged it across more than a decade of regular code reviews.

Google built the AI agent harness in early 2026 specifically to address the growing complexity of securing the Chrome browser. The system uses Gemini models to analyze code paths, identify potential security weaknesses, and suggest patches. In a blog post titled ‘Stronger with every update: How we are making Chrome and the web safer in the AI Era,’ Google described the system as a fundamental shift in how browser security is maintained.

The scale of the achievement is striking. The 1,072 bugs fixed across just two Chrome Stable release milestones represent more than the combined total from the 23 previous releases, a period spanning roughly two years. Google credited the AI system with not only finding vulnerabilities faster but also reducing the rate of false positives, which has historically slowed down automated security scanning efforts.

Security researchers have noted that the discovery comes amid a broader industry trend of AI being used both defensively and offensively in cybersecurity. OpenAI recently revealed that one of its models had autonomously exploited zero-day vulnerabilities in JFrog Artifactory to breach Hugging Face’s systems during a controlled test. The dual use of AI for both attacking and defending digital infrastructure has intensified debate about the need for stronger regulation.

The 13-year-old sandbox escape is particularly significant because it underscores the limitations of human-led security audits in increasingly complex software systems. Chrome’s security model relies on sandboxing web content to prevent malicious pages from accessing a user’s local files, and a bypass of that system could have been exploited by sophisticated attackers to steal sensitive data from millions of users.

Google said it will continue expanding the use of AI agents across its security infrastructure. The company has already begun deploying similar systems to other Google products beyond Chrome, though it declined to specify which ones. The announcement also coincides with the EU AI Act’s transparency obligations taking effect on August 2, which will require AI systems operating in Europe to disclose their use of artificial intelligence.

Sources:

Google Security Blog – Stronger with every update

BleepingComputer – Google says AI helped Chrome fix 1,072 security bugs

SecurityWeek – Google AI Uncovers 13-Year-Old Chrome Flaw

Author: Technology Desk

React to this dispatch
Share this dispatch Telegram X WhatsApp

discussion

Join the discussion

Your email address will not be published. Required fields are marked *