Google uses AI to fix 1,072 flaws in Chrome
Google/DeepMind
Google says AI tools now help analyze code and detect flaws faster, enabling Chrome versions 149 and 150 to fix 1,072 security vulnerabilities, more than the previous 23 versions combined. The company is also working on reducing the 'patch gap' and implementing dynamic patching to apply updates without restarting the browser.
Google announced on its security blog that AI tools now enable faster code analysis and detection of certain vulnerabilities. As a result, Chrome versions 149 and 150 fixed 1,072 security flaws, more than all fixes in the previous 23 versions combined, according to BleepingComputer. AI is now used at several stages of the security cycle: models analyze code, identify patterns similar to historical vulnerabilities, propose potential fixes, and assist teams during validation. Google notes that the main challenge has shifted from discovering vulnerabilities to validating, fixing, and distributing patches before attackers can exploit them, with the volume of identified flaws expected to grow as analysis tools improve. The company is focusing on reducing the 'patch gap'—the interval between patch publication and installation—especially for Chromium-based browsers like Edge, Brave, and Opera, and is speeding up release cycles, aiming for new major versions every two weeks. Google is also experimenting with 'dynamic patching' to apply security fixes without interrupting user sessions, testing automatic restarts when Chrome runs in the background without open windows, currently limited to macOS in Chrome 150. The goal is to keep the browser continuously updated without user intervention, reflecting a broader trend where AI both helps defenders and could be used by attackers to automate vulnerability research.
Source: Le Monde Informatique — IA —
original
