Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Google says AI pipeline helped Chrome fix 1,072 security bugs in June

Google said its Chrome 149 and 150 releases, both shipped in June 2026, fixed 1,072 security bugs combined, more than the prior two years, aided by an AI vulnerability pipeline.

D
Jul 30, 2026 · 1 min read

Google said its Chrome 149 and 150 releases, both shipped in June 2026, fixed 1,072 security bugs combined — more than the browser fixed across the prior two years. The company credited an AI-powered vulnerability pipeline, its Chrome security team said.

The comparison is stark: the previous 23 Chrome milestones, roughly two years of releases, fixed 1,036 bugs in total. Google said the pipeline includes a Gemini-based agent harness, built in early 2026, that searches the Chrome codebase for vulnerabilities, triages them and generates patches for human review.

One find stands out. The system surfaced a sandbox-escape bug that had sat undetected in the codebase for more than 13 years. Sandbox escapes are among the most serious browser flaws because they let malicious code break out of the isolated environment meant to contain it.

Google also said 97% of first-party Chrome code now compiles cleanly under strict buffer-safety warnings, and that automated tools blocked more than 20 vulnerabilities, including one critical S1+ issue, from reaching production in May 2026 alone. Chrome carries more than 2,300 third-party dependencies, about 1,700 of which ship to users.

The figures are Google’s own and were not independently verified, and a higher bug count can reflect better detection and more scrutiny rather than more underlying flaws. Even so, it is one of the more concrete claims yet that AI code-analysis tools are changing the economics of finding and fixing software vulnerabilities at scale.

More news