Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

The Google Chrome security team is significantly increasing its patch frequency to twice a week due to a surge in vulnerability discoveries. This spike is largely attributed to the integration of AI tools into their internal security workflows.
Why it matters
It highlights a major shift in cybersecurity where AI is being used both to discover and patch vulnerabilities at an unprecedented scale, potentially setting a new industry standard for software maintenance.
In a report published Thursday, the Chrome security team says the browser's two major version releases in June included fixes for 1,072 security bugs—more patches than the team shipped in the prior 23 big releases combined. And though many of these bugs come from researcher submissions, the spike has largely been driven by the Chrome security team’s rapidly evolving internal process for using AI tools in vulnerability discovery, triage, and patch development.
“In chrome we’ve been using machine learning—using AI before it was called AI—to help find vulnerabilities in particular and automate security fuzz testing work since at least 2012. It’s been a huge part of how we find vulnerabilities and empower developers,” Parisa Tabriz, Chrome’s vice president and general manager, tells WIRED. “But I do think this year is very different. It really feels like an inflection point both for offense and defense.”
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in