Google fixed more Chrome bugs in June than over the past two years, thanks to AI

Google's Chrome security team is leveraging Large Language Models to accelerate the discovery and patching of software vulnerabilities. By using AI agents like Big Sleep and Gemini, the team has successfully identified long-standing bugs, including a 13-year-old sandbox escape.
Why it matters
The integration of AI into cybersecurity workflows represents a paradigm shift in how software companies manage risk, potentially reducing the window of exposure for critical exploits.
How Chrome is using AI to improve vulnerability discovery, triage, and patching.
We’re living through a massive shift in the software security industry. Large Language Models (LLMs) are unlocking unprecedented capabilities for automated vulnerability discovery, scaling far beyond the limits of human security expertise, and requiring new approaches for staying ahead of attackers.
This means deploying AI models at scale to find and fix hundreds of security bugs, faster than ever, with the goal of achieving greater resilience and comprehensive remediation.
Some software bugs have security implications. While a purely functional bug might result in a frustrating UI freeze, a security bug (or vulnerability) can be used to build an exploit. Exploits allow attackers to perform malicious actions on a victim’s computer, such as reading private data, or controlling their machine without their knowledge.
Once a security bug enters the codebase, its life cycle proceeds as follows:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in