Over 1,800 patches in seven months: Google’s AI transforms Chrome security and finds a 13-year-old vulnerability
Google's Gemini-based AI fixed over 1,800 Chrome vulnerabilities in seven months, discovering a 13-year-old sandbox escape flaw and automating patches.
Illustrative image generated with AI
An unprecedented wave of fixes
In the first half of 2026, Google fixed more than 1,800 vulnerabilities in Chrome—a volume that obliterates all previous records. Versions 149 and 150 alone delivered 1,072 security fixes, surpassing the combined total of the twenty-three prior milestones. The latest release, Chrome 151, solidified the trend with another 370 patches, closing a quarter—from April to July—where the pace of fixes stayed consistently high. Behind this acceleration is a proprietary agentic harness built on Gemini, Google’s language model, active since the start of the year.
The system does more than find bugs: it validates, triages, and often directly produces the patch. Google is already experimenting with biweekly security releases to shrink the patch gap—the time between discovery and patch delivery.
CVE-2026-3545: a sandbox escape hidden since 2013
Among the harness’s most significant finds is CVE-2026-3545, a critical vulnerability with a CVSS score of 9.8 that let a compromised renderer read local files through crafted HTML pages. The flaw had been present in the browser for thirteen years. It was identified and patched in early May with the release of Chrome 145.
The potential impact was severe: an attacker who took over the rendering process could bypass sandbox boundaries and access sensitive data on the victim’s hard drive. The update to Chrome 145 neutralized the issue, but the vulnerability’s lifespan shows how entire classes of bugs can survive traditional review processes.
The harness’s ingredients: Git history, past CVEs, and a “critic” agent
The infrastructure powering this wave of patches combines multiple elements. The knowledge base includes Chrome’s entire Git history and a structured archive of historical CVEs, allowing search models to be trained on known vulnerability patterns. A “critic” agent consults SECURITY.md files to refine results and reduce false positives. Analysis is performed on static code inside air-gapped machines, with no need for execution.
Beyond discovery, the AI is used for automated triage and to generate fixes. The stated goal is to achieve a dynamic patching system that removes the need for a browser restart after an update, though a restart remains necessary for now.
Rust, MiraclePtr, and “spanification”: the strategy to eliminate bugs at the root
AI isn’t the only lever Google is pulling. The company is working to extinguish entire categories of memory-related vulnerabilities. Extending MiraclePtr and introducing MiracleObject on the GPU thread aim to make use-after-free bugs harmless. So-called “spanification” combats out-of-bounds accesses, while new protections cover integer overflows.
On the language side, the migration to Rust is accelerating: Google has built a centralized SDK, is writing new modular components in Rust, and experimenting with user interfaces based on HTML, CSS, and TypeScript. Third-party dependencies are also being moved to automated update pipelines, reducing risks inherited from external libraries.
What to do now
Anyone using Chrome should update to the latest release immediately. As of August 2, 2026, the reference version is Chrome 151, which includes 370 security fixes. A browser restart is still required to apply patches. Google recommends enabling automatic updates and not delaying restarts, because the accelerated discovery narrows the exposure window but demands user responsiveness.
Sources
This article is an original reworking based on the sources below.




