Google’s Chrome bug surge shows AI is changing software security
Lead
AI’s impact on cybersecurity is no longer just a forecast. Google says its internal AI tools helped Chrome patch 1,072 security flaws in the two browser versions released in June. That is more than the 1,036 fixes shipped across the previous 23 Chrome versions over roughly two years.
Key points
- A sharp jump in Chrome fixes: According to Google, Chrome 149 and Chrome 150 together addressed 1,072 security bugs, surpassing the total fixed in the prior two-year stretch.
- AI is part of the explanation: Google links the surge to internal AI systems and models such as Gemini, which are being used to identify and repair vulnerabilities earlier.
- The economics of security are shifting: Chrome engineering director Doug Turner told TechCrunch that LLMs have changed the economics of cybersecurity by turning vulnerability discovery into an automated, industrial-scale operation.
- The pattern extends beyond Google: Microsoft recently disclosed a record 570 security fixes across its products in a Patch Tuesday release and also cited AI as a factor.
- Not every major vendor shows the same curve: TechCrunch noted that Apple has patched 482 bugs in 2026 so far, a pace roughly comparable with last year and with its 2015 total, based on an independent count.
Why it matters
The most important part of Google’s announcement is not simply the high number of fixes. It is the change in the cost and speed of finding bugs. Traditional security work has depended heavily on expert review, fuzzing, manual triage and long engineering cycles. AI-assisted workflows can scan more code, surface more candidate issues and help teams move faster from discovery to patch.
That does not automatically make the internet safer. The same broad capability can help attackers find flaws more cheaply and at larger scale. If vulnerability discovery becomes increasingly automated, defenders will need equally automated systems for prioritization, patch generation and validation.
For Chrome users, the practical advice remains simple: keep the browser updated. For software makers, the message is broader. AI is moving from a peripheral productivity tool into the core security pipeline, touching discovery, analysis, triage and remediation. Google’s June patch numbers may be an early sign of a new era in which AI finds more bugs, humans verify the fixes, and vendors race to close gaps before adversaries can exploit them.
Source: TechCrunch AI
Comments
Checking sign-in status...
Loading comments...