Google's AI is uncovering Chrome bugs that have evaded human detection for years.
Here’s how Google is leveraging Gemini AI to more efficiently identify, prioritize, and resolve security vulnerabilities in Chrome than ever before.
I had always thought that Chrome’s frequent update alerts were simply part of routine maintenance, with occasional genuinely beneficial features added. However, I’ve learned that some of these updates are addressing vulnerabilities that have lingered unnoticed in the browser’s code for over ten years.
So, how is AI aiding in the detection of these bugs?
Google has developed an AI agent powered by its proprietary AI model, Gemini, specifically designed to scan the entirety of Chrome’s codebase for security weaknesses, and it has already shown impressive results.
Among the various fixes, one notable issue was a sandbox escape vulnerability that allowed a compromised component of the browser to deceive Chrome into accessing local files. What’s particularly alarming is that this flaw had remained unnoticed for over 13 years.
The system now also manages triage, automating the initial processing of incoming bug reports by filtering out spam, replicating the issue, and assigning severity ratings. This task used to require human intervention, taking five to thirty minutes per report.
Once a bug is validated, a "fixing agent" produces potential patches, which are then evaluated by a "critic agent." Test-writing agents confirm the functionality across all platforms supported by Chrome before a human developer reviews anything. Google states that this process saves hundreds of developer hours each month.
So, does this actually mean more bugs are being resolved?
In just two recent Chrome updates, versions 149 and 150, Google addressed a total of 1,072 security vulnerabilities—more than what was fixed in the previous 23 updates combined.
Google is also striving to reduce the “patch gap,” which refers to the delay between a fix being created and it actually being applied to your browser. They are testing the rollout of two security updates each week instead of one and are exploring “dynamic patching” that could eventually eliminate the need to restart Chrome for most updates.
However, it’s important to clarify that this does not imply that Chrome now has more bugs than before. It signifies that Google is finally detecting the vulnerabilities that have always existed, and doing so at a faster pace than attackers can exploit them.
Other articles
Google's AI is uncovering Chrome bugs that have evaded human detection for years.
Google reports that Chrome's new AI-driven security system identified a 13-year-old vulnerability and assisted in resolving more than 1,000 security issues in only two recent updates.
