Chrome browser security and AI-driven vulnerability management
The developments in this story so far, most recent first.
-
· date approximate · Development
Chrome shifts to twice-weekly security patches
-
· date approximate · Background
Chrome versions 149 and 150 were released.
In June 2025, Google released Chrome versions 149 and 150. These two releases addressed 1,072 security bugs, a total that exceeded the number of fixes provided in the previous 1,036 issues across 23 releases over the preceding two years.
The release timeline marked a jump in version numbers from 126 in June 2024 to versions 149 and 150. This period was described by Chrome leadership as an inflection point for both offense and defense, characterized by a near-term spike in vulnerability fixes.
-
· date approximate · Background
Chrome version 126 was released.
Chrome version 126 was released in June 2024, marking a period of heightened security activity. According to reports, Google fixed 1,072 security bugs in its two Chrome releases that month—exceeding the total number fixed in the previous 23 releases over two years [1][2].
The update came as Google accelerated its use of AI for vulnerability management. Chrome’s director of engineering Doug Turner stated that large language models had "fundamentally shifted the economics of cybersecurity," making vulnerability discovery an industrial-scale operation [7]. The team applied models like Gemini to preemptively fix vulnerabilities [8].
Chrome vice president Parisa Tabriz described the period as an "inflection point both for offense and defense," while noting that a "new equilibrium" might follow the near-term spike in fixes [3][9].
-
· date approximate · Background
Chrome has been using machine learning for vulnerability discovery and fuzz testing.
Chrome has utilized machine learning as part of its security infrastructure since at least 2012. These efforts have specifically focused on vulnerability discovery and fuzz testing.