SendTech Times
News
SYSTEMS SHIFT:

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs

Newsroom brief

BleepingComputer reported that Google attributed 1,072 Chrome security bug fixes to Chrome 149 and Chrome 150, while faster patch delivery remains part of the browser security plan.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs
Image source: BleepingComputer

Google's Chrome 149 and Chrome 150 fixed 1,072 security bugs, BleepingComputer reported, giving the browser team a larger test of AI-assisted vulnerability management than its earlier fuzzing work.

The contrast is in the workflow.

AI tools are finding more issues, but Chrome still has to move confirmed fixes to users before attackers can study public code changes and work backwards to the underlying vulnerability.

Chrome Fix Count Exceeded 23 Earlier Milestones

Google said the two-release total exceeded the combined security-fix count from the previous 23 Chrome milestones.

The company has also received more Chrome Vulnerability Reward Program submissions by March 2026 than it received during all of 2025.

The higher intake has changed how the browser team handles reports.

Automated triage now removes spam and duplicate submissions, reruns proof-of-concept exploit material, grades severity and sends confirmed issues to the right developers.

Google estimates that the process saves hundreds of developer hours each month.

AI Agents Move Across Chrome Security Workflow

Large language models are now part of discovery, reproduction, severity assessment, developer assignment, candidate patch creation and test generation.

Google began applying LLMs to security fuzzing in 2023, then worked with Project Zero on Naptime, which provided AI models with specialised vulnerability research tools.

The AI work later moved into Big Sleep, a vulnerability discovery agent developed with Google DeepMind and Project Zero.

That system covered the V8 JavaScript engine and graphics components before Google created a Gemini-powered agent harness in early 2026 for broader Chrome codebase searches with fewer false positives.

Google said the system identified a sandbox escape that had sat in Chrome for more than 13 years; exploitation would have allowed a compromised renderer process to break isolation and make the browser read local files.

The browser team is also adding SECURITY.md files that describe trust boundaries and threat models.

Those files give AI systems more context when deciding whether a code path has security implications, while fuzzing remains part of the existing testing stack rather than being replaced.

Patch Gap Moves To Faster Browser Updates

Patch delivery is becoming part of the same security cycle.

After a security fix is committed to the public Chrome repository, adversaries can review the diff and attempt to reconstruct the bug before users receive the update.

The browser roadmap now shortens both major and security-release timing.

Google is shifting Chrome to major versions every two weeks, continuing weekly security updates and testing a twice-weekly security-release rhythm.

The Chrome 150 macOS plan allows the browser to restart automatically in the background to apply a pending update when no windows are open.

Dynamic patching is the longer-term goal because it would let Chrome apply updates without restarting the browser.

User adoption of faster release and restart behaviour remains the condition that determines how much of the AI-assisted fix pipeline reaches installed browsers in time.

Share this article
inXf

Related articles

More
WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow
Cybersecurity

WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow

BleepingComputer reported that Group-IB investigated a WindRelay and SpyNote Android malware combination that used social engineering, remote device access and NFC relay fraud to move from a phone call to financial theft.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda
Cybersecurity

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda

CISA added exploited Android and Linux vulnerabilities to its Known Exploited Vulnerabilities catalog. The Android flaw affects Android 14 through 16, while the Linux issue centers on older kernel branches and cgroups v1 container environments. The immediate test is whether agencies and infrastructure operators apply vendor updates or mitigations by CISA's June 5 deadline.

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths
Cybersecurity

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths

Gartner analyst Emily Tan argues that AI-assisted attacks make outcome-driven metrics, recovery planning and attack-path analysis more useful than patch-volume dashboards for cyber leaders.

Fleuret AI Raises €4M For Continuous AI Pentesting Platform
Cybersecurity

Fleuret AI Raises €4M For Continuous AI Pentesting Platform

Tech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow
Cybersecurity

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow

A ransomware-focused threat actor adopted an AI-built toolkit for Active Directory discovery and endpoint detection and response evasion. Sophos found Cursor and Claude Opus agents assisted development, with close to 80 modules tested against more than 70 techniques. The practical question is whether defenders can shorten validation cycles as AI accelerates the move from offensive research to working malware components.

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test
Cybersecurity

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test

CISA ordered U.S. federal agencies to patch Oracle WebLogic Server systems affected by CVE-2024-21182 after active exploitation was observed. Shodan tracks more than 1,592 exposed WebLogic servers vulnerable to the flaw, including 961 on version 12.2.1.4.0 and 631 on version 14.1.1.0.0. The immediate test is whether public- and private-sector defenders apply Oracle fixes or remove exposed systems where mitigations are unavailable.

Hugging Face Hack Pushes AI Agents Into Cybersecurity Spotlight
AI

Hugging Face Hack Pushes AI Agents Into Cybersecurity Spotlight

CNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.