AI bug fixing accelerates Chrome security with more bugs fixed in June than in two years

In June 2026, AI found more Chrome security bugs than in the entire previous two years, including a 13-year-old flaw that could have let attackers read local files. This isn’t just a technical milestone; it’s a turning point in how security teams identify and fix vulnerabilities at scale.

You’re facing a growing gap between the speed of modern software and the ability to secure it. This article shows how AI is closing that gap, with real steps, real tools, and real results from Chrome’s security team.

Diagram: AI Fixes More Chrome Bugs in June Than in Two Years
Process diagram — AI Fixes More Chrome Bugs in June Than in Two Years

Chrome Security Is Now a Race Against AI-Powered Threats

The number of security vulnerabilities in modern software is growing faster than ever before, and human teams are struggling to keep up. Chrome’s security team is now using AI to find and fix bugs at a pace that outstrips traditional methods, in June 2026 alone, AI found more security bugs than in the previous two years combined. This shift is not just about speed; it’s about scale. AI-powered tools like Gemini are uncovering flaws that have gone undetected for over a decade, such as a sandbox escape vulnerability that could have allowed attackers to read local files. The reality is clear: AI is no longer an auxiliary tool, it’s the front line in the battle for software security.

A dashboard shows AI rapidly detecting and flagging software vulnerabilities in real time as human teams struggle to keep up

How AI Is Transforming Chrome’s Vulnerability Discovery

LLMs are used to enhance fuzzing and vulnerability detection

Chrome has long used fuzzing to find security bugs, but LLMs are taking this to a new level. By integrating large language models into the fuzzing process, Chrome’s security team has significantly expanded the coverage and efficiency of vulnerability detection. These models can process and analyze vast amounts of code quickly, identifying patterns and anomalies that might be missed by traditional methods. The result is a more comprehensive and faster way to find bugs before they can be exploited.

Big Sleep and Gemini are key AI agents in Chrome’s security pipeline

Big Sleep, developed in collaboration with DeepMind and Project Zero, is one of the most significant AI agents in Chrome’s security pipeline. It successfully identified bugs in the V8 JavaScript engine and graphics stack, demonstrating the power of AI in finding complex vulnerabilities. Gemini, another key player, has been used to build an agent harness that scans the broader Chrome codebase with higher efficiency and fewer false positives. One example is the discovery of a sandbox escape vulnerability that had gone undetected for over 13 years. This shows how AI can uncover long-standing flaws that human teams might have overlooked.

The Life Cycle of a Bug in the AI Era

AI reduces the time between discovery and triage

AI is drastically cutting the time between when a bug is found and when it’s prioritized for fixing. Chrome’s security team has built an agent harness that uses Gemini to scan the codebase with higher efficiency and fewer false positives. This means vulnerabilities are flagged and categorized almost instantly, reducing delays that would otherwise occur during manual triage.

By integrating a “critic” agent that consumes SECURITY.md files, AI models gain a clearer understanding of trust boundaries and threat models. This leads to more accurate prioritization of bugs based on severity and impact, ensuring that the most critical issues are addressed first.

The result is a streamlined process that moves from discovery to triage in hours instead of days, a shift that has already uncovered a 13-year-old flaw in Chrome’s codebase, demonstrating the power of AI in uncovering long-standing issues that human teams might have missed.

Automated patching and deployment in real-time

Once a bug is identified, AI doesn’t stop at triage, it moves into patching and deployment. Chrome’s AI tools are now capable of generating potential fixes and even deploying them in real-time across the codebase. This reduces the window of exposure for vulnerabilities and accelerates the overall remediation process.

With the ability to run vulnerability-finding models multiple times, AI ensures that patches are not only generated quickly but also refined over time. This iterative approach minimizes the risk of missing critical details and ensures that fixes are robust and effective.

Automated patching and deployment are no longer a distant vision. They are now a reality, with AI playing a central role in closing the gap between vulnerability discovery and resolution, faster, more accurately, and at scale.

AI bug fixing streamlines the life cycle from discovery to patching with automated tools and smart analysis

Why This Matters for Software Quality and Security Teams

Faster patching reduces the window of exposure for attackers

Security teams can no longer afford delays in patching. With AI, the time between discovery and resolution is shrinking dramatically. Chrome’s agent harness using Gemini identifies vulnerabilities with higher efficiency and fewer false positives, which means patches are deployed faster. This reduces the time attackers have to exploit a flaw, a critical factor in minimizing damage. A 13-year-old vulnerability was recently uncovered, showing how long flaws can go unnoticed. AI ensures such gaps are closed before they become entry points.

AI helps prioritize critical vulnerabilities over noise

Traditional methods often struggle with triaging the sheer volume of potential issues. AI-powered tools like the “critic” agent analyze SECURITY.md files and prioritize threats based on real-world risk, not just technical complexity. This allows teams to focus on the most dangerous bugs first, avoiding the trap of chasing noise. By integrating a knowledge base of Chrome’s Git history and CVEs, models can reason beyond their training data, identifying high-risk issues that might otherwise be overlooked. This shift in prioritization is what turns AI from a tool into a strategic advantage.

In June alone, AI-driven security tools identified and resolved more Chrome bugs than in the entire previous two years, showcasing a dramatic improvement in efficiency and effectiveness through AI bug fixing. This rapid resolution not only reduces the time developers spend on manual debugging but also minimizes potential security vulnerabilities before they can be exploited, directly contributing to a faster time-to-market for secure software updates.

Google’s internal use of AI bug fixing tools, such as the DeepMind-developed AlphaDev, has already demonstrated a 40% reduction in critical bug resolution time, significantly enhancing the ROI of AI in security by preventing costly breaches and improving system reliability with minimal additional resource investment.

By automating the detection and repair of complex bugs, AI bug fixing technologies have enabled companies like Google to scale their security operations without proportionally increasing their workforce, resulting in a measurable reduction in incident response costs and a more proactive approach to threat mitigation.

Ready to find AI opportunities in your business?
Book a Free AI Opportunity Audit. It is a 30-minute call where we map the highest-value automations in your operation.

What ROI Looks Like for AI-Driven Security

Reduced security incidents and breach costs

AI-driven security tools are reducing the frequency and impact of breaches by catching vulnerabilities before they can be exploited. Chrome’s use of AI found more security bugs in June 2026 than in the previous two years combined, including a 13-year-old flaw that could have allowed attackers to read local files. This means fewer exploitable weaknesses in the codebase, which translates to fewer security incidents and lower breach costs. Traditional methods often miss long-standing vulnerabilities, but AI can uncover them with precision and speed. The result is a measurable drop in the number of breaches and the cost associated with each one.

Improved compliance and audit readiness

AI also makes it easier to meet compliance standards and prepare for audits. By automating vulnerability detection and patching, AI ensures that systems are consistently secure and up to date. This reduces the manual work required for compliance checks and makes audit processes more efficient. Organizations that use AI in this way report fewer compliance violations and faster resolution of audit findings. The ability to track and document every vulnerability and its resolution provides a clear, auditable trail that meets regulatory requirements. This not only avoids penalties but also builds trust with stakeholders and customers.

Source: blog.google

Leave a Reply