Skip to content
Beveiligingsnieuws

Google’s AI-Driven Chrome Fixes Surpass Past Years

Chrome bugs verholpen

Google says it has made a major leap in how quickly it can address security problems in its Chrome browser—using internal AI tools to find and fix vulnerabilities at a faster pace. In a statement shared with TechCrunch, the company claims that the latest milestone updates shipped in June included far more security fixes than the total accumulated over the previous two years.

What stands out is not just the number of patched issues, but the message behind the numbers: Google argues that AI has changed the “economics” of cybersecurity by turning vulnerability discovery into something closer to an automated process. For security teams, that shift has implications for speed, scale, and how defenders plan their response.

1,072 Chrome security bugs in two June updates

Google reported that it fixed 1,072 security bugs across the last two versions of Chrome released in June. Those releases are considered “milestones” by the company, and together they cover more fixes than were patched in the prior 23 Chrome versions released across the preceding two-year period.

In that earlier span, Google says the total number of security bug fixes was 1,036. So, according to Google’s own comparison, the two June releases slightly outpaced the sum of the preceding window.

While the headline is a large quantity of fixes, the broader takeaway is that the fixes are arriving in a more compressed timeframe. That can matter in practice, because vulnerabilities often have a lifecycle: they are discovered, potentially exploited, and then mitigated through updates. A faster patch cadence can reduce the time window in which systems remain exposed.

Google attributes the jump to AI tools

Google’s explanation centers on AI assistance for vulnerability discovery and remediation. The company shared that it has been using internal AI capabilities—models such as Gemini—to help preemptively fix security issues and reduce the gap between defenders and adversaries.

Doug Turner, Chrome’s director of engineering, said that large language models have “fundamentally shifted the economics of cybersecurity.” In his view, vulnerability discovery has moved toward an automated, industrial-scale operation rather than a primarily manual, slower workflow.

Turner also stated that by applying models like Gemini, Google can identify and address issues earlier—“outpacing” adversaries and making Chrome safer with each update. The underlying claim is that AI doesn’t replace security engineering, but accelerates parts of the pipeline that traditionally limited how quickly teams could respond.

Why security teams feel pressure to use AI too

AI in cybersecurity has been discussed for years, but the practical debate has always been about scale. As LLM-style systems grew, cybersecurity experts warned that AI-powered discovery could lead to an ever-growing volume of bugs to investigate and patch—potentially faster than defenders could keep up with traditional methods.

Google’s reported metrics are being presented as evidence that this forecast is starting to reflect reality. The company says its own chart—released alongside a white paper describing its work to use AI to find flaws and patch them faster—shows an exponential increase in security fixes over time.

In other words, Google is not only publishing totals; it is also pointing to a trend: more issues are being patched as time goes on, and the growth is accelerating.

Chrome milestone releases and the timing of the trend

Google’s milestone framing helps contextualize the comparison across time. The company references Chrome 126 as a June release in 2024, then contrasts it with the most recent milestone releases it counts as part of the June 2026 window: Chrome 149 and Chrome 150.

By comparing those milestone updates, Google is essentially arguing that the recent cadence and fix volume are not accidental—they represent a measurable change relative to earlier release cycles. That shift is important for readers trying to understand whether this is a one-off spike or part of a larger movement in vulnerability management.

The key point is that the “last month” window Google refers to is associated with the same June releases that produced the 1,072 security bug total. That structure makes the comparison clearer: two June versions delivered a patch count that exceeded the previous two-year aggregate.

Microsoft reports a record Patch Tuesday

Google is not the only company reporting a surge in vulnerability fixes. Earlier in the month, Microsoft announced that it patched a record 570 security flaws across its products as part of its monthly Patch Tuesday cycle.

Microsoft attributed the jump to its own use of AI. While Microsoft’s environment is broader than a single browser—and its product lines include operating system and developer tooling—its message aligns with Google’s: AI can help security teams process vulnerabilities faster and at larger volume.

Taken together, the two announcements suggest that AI is becoming part of the standard toolkit for security operations, especially where teams face constrained timeframes between discovery and patching.

Apple’s reported counts appear to be different

Not every company appears to be showing the same steep acceleration in published fix counts. An independent count referenced by TechCrunch indicates that Apple has patched 482 bugs in 2026 across its products.

Based on that estimate, Apple’s progress is described as being roughly on pace to match or potentially surpass the number of fixed bugs from last year. It is also said to be roughly equal to the number of bugs Apple patched in 2015.

TechCrunch contacted Apple for comment but did not receive a response. As a result, readers should treat the comparison as directional rather than fully explained—different companies may measure, disclose, or categorize vulnerabilities differently.

What “AI-driven Chrome fixes” could mean for users

For everyday users, the most practical impact is that browsers can become safer more quickly when security teams can reduce time-to-patch. If AI helps teams find issues sooner and ship fixes within a shorter cycle, then users benefit from reduced exposure.

For organizations, this can affect patch management planning. Higher fix volumes clustered in fewer update releases may require closer monitoring of update schedules, quicker rollout procedures, and more attention to what changed between releases.

It also raises a question: when vulnerability discovery becomes more automated, defenders may receive a steady stream of items to evaluate. That can make triage and prioritization even more important, because fixing more bugs is only one part of the security challenge.

The bigger story: shifting cybersecurity workflows

Google’s central claim is that AI is changing the “economics” of cybersecurity by scaling vulnerability discovery and supporting preemptive patching. Whether measured by bug counts, release cadence, or the speed of remediation, the message is that defenders are being pushed toward industrial-scale processes to keep up with modern threat activity.

The reported numbers—1,072 security bugs fixed across the two latest June Chrome milestone releases—are being used as a concrete indicator of that shift. Meanwhile, Microsoft’s record Patch Tuesday and other industry signals suggest that this pattern is not isolated to one vendor.

Still, comparisons across companies should be approached carefully. Different disclosure practices, product scopes, and counting methodologies can influence published totals. Even so, the overall direction—AI becoming a core enabler of faster security work—appears consistent across multiple major technology players.

Conclusion

Google says its AI-driven Chrome fixes delivered a standout outcome: 1,072 security bugs patched across two June releases, surpassing the total fixes from the previous two years combined. The company links the result to internal AI tools and models like Gemini, arguing that LLMs have fundamentally shifted vulnerability discovery toward automation at scale.

As more companies report similar trends, the security industry is likely to keep evolving its workflows around AI to reduce the gap between discovery and defense. For users and organizations, the goal is simple: fewer vulnerabilities linger unpatched for longer.

Source: https://techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/