- Google fixed 1,072 security bugs in Chrome versions 149 and 150, surpassing the total from the prior 23 milestones combined.
- A critical sandbox escape vulnerability (CVE-2026-3545, CVSS 9.6) went undetected in Chrome’s codebase for over 13 years before discovery by Google’s Gemini AI.
- Google is accelerating defenses with two security releases per week, dynamic patching, and a shift to memory-safe languages like Rust.
Google on Thursday announced it fixed 1,072 security bugs in Chrome versions 149 and 150, surpassing the total flaws resolved across the prior 23 milestones combined, according to a company blog post. The development comes amid an exponential surge in vulnerability discovery fueled by large language models, with issues now being flagged at a faster rate than companies can fix them.
Google resolved 370 flaws in its latest Chrome 151 patch, 349 of which were reported internally, with seven marked critical in severity. NVD statistics show 46,872 flaws recorded so far in 2026, nearing the 49,920 vulnerabilities reported for all of 2025.
One critical sandbox escape in the Navigation component (CVE-2026-3545, CVSS 9.6) could trick the browser into reading local files and was patched in March. Google said the flaw was discovered via an agent harness leveraging its Gemini models and remained undetected in source code for more than 13 years, according to Chromium issue tracking.
Consequently, Google is transitioning to a two-week release cadence for major milestones alongside weekly security updates, piloting two security releases per week in response to AI-powered attacks. “Every security bug that reaches Chrome Stable, regardless of whether it was discovered internally or reported externally, is documented and disclosed publicly as a standard best practice,” the company said.
Google is exploring dynamic patching that replaces background child processes with updated binaries without requiring a browser restart. The company is also eliminating entire bug classes by hardening the runtime, transitioning to memory-safe languages like Rust, and moving all third-party dependencies onto automated update pipelines.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
