AI SafetyAgents 🇺🇸 03.08.2026 16:01

Google used AI agents to find and fix 1,072 Chrome security bugs in 60 days

Google/DeepMindGoogle/DeepMind DeepMindDeepMind
Google's Chrome security team used AI agents, including Gemini-based tools, to find and fix 1,072 security bugs in two Chrome releases, surpassing the total fixed in the prior 23 milestones. The AI workflow saved hundreds of hours of developer time per month, but also highlights an escalating arms race as attackers can use similar AI.
Google's Chrome security team detailed in a blog post how it used AI agents to improve vulnerability discovery, triage, and patching. In milestones M149 and M150, the AI found and fixed 1,072 bugs, more than the total fixed in the previous 23 milestones combined. The AI workflow includes a four-stage triage operation: filtering noise, reproducing bugs, enriching reports with metadata, and handing off to human developers. Additionally, a multiagent workflow uses a fixing agent and a critic agent to generate and evaluate candidate fixes, followed by test-writing agents that run Chrome across supported platforms. This process saves weeks of developer time per month. A specific example: Gemini found a sandbox escape vulnerability in Chrome that existed since 2013 and passed test suites for over a decade. Google is also working to accelerate patch delivery, moving to a two-week release cadence and potentially two security releases per week, with dynamic patching to minimize restarts. The implications are significant: AI accelerates both attack and defense, leading to a faster arms race where code evolves at a pace of years compressed into months.
Abbreviations
QA = Quality Assurance — обеспечение качества
Source: ZDNet AI — original
Our earlier posts on this topic ↓
Fresh news