Google says AI fixed 1,072 Chrome security bugs in two releases

Google says artificial intelligence helped patch 1,072 security vulnerabilities across Chrome 149 and Chrome 150, surpassing the total fixed in the previous 23 releases combined, according to a statement from the company.
Google uses large language models throughout its vulnerability management process, including discovering flaws, reproducing reports, determining severity and generating patches. The company began using LLMs for security fuzzing in 2023 and has since developed AI-powered systems including Big Sleep, which found flaws in Chrome's V8 JavaScript engine, and a Gemini-powered agent that searches the broader codebase. One vulnerability discovered by the system was a Chrome sandbox escape that had remained in the code for more than 13 years.
Google is also automating vulnerability triage, including filtering duplicates and assigning severity ratings. The company estimates this automated process saves hundreds of hours of developer time each month. In May, these systems prevented more than 20 vulnerabilities from reaching production, including one classified as critical, Google said, Lawrence Abrams reports for BleepingComputer.