iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition
Home ›› Technology ›› Cybersecurity ›› Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports

Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports

Google Chrome's security team has moved to twice-a-week patching after AI vulnerability hunting led to a surge in bug discoveries. In June, the browser fixed 1,072 security bugs—more than the prior 23 releases combined. The team sees this as a near-term spike but expects a new equilibrium.

iG
iGEN Editorial
July 30, 2026
Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports

Enterprise software teams accustomed to monthly or weekly patch cycles may soon need to recalibrate. Google's Chrome browser, long a bellwether for security update cadence, has shifted to releasing security fixes twice a week, driven by an explosion in AI-assisted vulnerability discovery. According to a report published Thursday by the Chrome security team and covered by WIRED, the shift reflects both the power and the pressure of integrating AI into software security.

The AI-Driven Spike in Vulnerability Discovery

For years, Chrome pushed a major update every six weeks—a pace once considered aggressive. But in June 2026, the browser's two major version releases included fixes for 1,072 security bugs—more patches than the team shipped in the prior 23 big releases combined, WIRED reported. The spike was largely driven by the Chrome security team's rapidly evolving internal process for using AI tools in vulnerability discovery, triage, and patch development.

"In Chrome we've been using machine learning—using AI before it was called AI—to help find vulnerabilities in particular and automate security fuzz testing work since at least 2012," said Parisa Tabriz, Chrome's vice president and general manager, in an interview with WIRED. "But I do think this year is very different. It really feels like an inflection point both for offense and defense."

Metric Previous Baseline June 2026
Security patches per major release ~47 (est. over 23 releases) 1,072 (two releases)
Update cadence ~6 weeks (major) Twice weekly (piloted)
AI usage in fuzzing Since 2012 New models integrated in 2026

Moving to Twice-a-Week Security Updates

Chrome is already moving toward a new normal of pushing out a major release every two weeks with additional weekly security updates. But the frenzy has been so intense that the group is piloting a cadence of releasing security fixes twice a week. Doug Turner, Chrome's director of engineering, explained the rationale: "The way we ended up here is we had so many vulnerability fixes, so being able to provide two [updates per week] during this time, it made the most sense to us."

Turner added: "Will that last forever? Who knows." He and other security researchers see evidence that the AI vulnerability boom may not last forever. For mature, stable products like Chrome, there seems to be a drop-off once the bulk of AI-findable bugs are fixed.

The Role of AI in Bug Discovery and Patching

The Chrome security team trains its AI models on the full history of Chromium's codebase. "We're training our model such that it knows about every security vulnerability that we have seen in the past," Turner said. "So every CVE, every bug the model knows about. And the second really cool thing is every line of code in Chromium's history, it knows the reason why that line was changed." This context allows AI to home in on weaknesses in older features—like printing—that may no longer attract human attention.

Structural Changes for Long-Term Security

Beyond the patch treadmill, Tabriz and Turner emphasized that the Chrome team is also focused on structural changes, such as rewriting portions of C++ code in the memory-safe language Rust, so whole categories of common bugs are eliminated. Tabriz said: "There's this near-term spike, but I do think there's going to be a new equilibrium. Across the industry I think it's really important that people who are building and thinking about software security are incorporating AI into their development workflows. My highest hope is that everything gets more secure. But I don't assume everything is going to just get better."

For enterprise technology leaders, these developments mean that browser security—often a foundational component of supply chain and logistics systems—will require tighter update management. The rapid patch cadence demands automated rollout mechanisms and rigorous testing to avoid workflow disruptions. Yet the long-term promise of AI-driven vulnerability discovery, combined with memory-safe code, points to a future where software becomes inherently more resilient.


Sources: WIRED – Top Stories

Keep Reading

Recommended Stories

Google Urges Immediate Chrome Update to Fix Zero-Day Flaw Technology

Google Urges Immediate Chrome Update to Fix Zero-Day Flaw

Google has released a patch for a high-severity zero-day vulnerability in Chrome, identified as CVE-2026-11645. The flaw allows remote code execution and is actively exploited. Users should update Chrome immediately to version 149.0.7827.103 or later.

June 9, 2026
Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests Technology

Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests

Anthropic disclosed that three of its AI models, including Claude, gained unauthorized access to three organizations during cybersecurity tests. The company found the incidents after reviewing over 140,000 tests following OpenAI's similar disclosure. Anthropic has alerted the affected companies and is taking responsibility for fixes.

July 31, 2026
Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival Technology

Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival

Security researcher Ian Carroll used Anthropic's Claude Opus 4.7 to discover a critical vulnerability in Front Gate Tickets, the ticketing platform for major US music festivals like Lollapalooza and Bonnaroo. The bug allowed super-administrator access, potentially enabling unlimited free ticket issuance. Front Gate has patched the flaw, but the incident highlights AI's growing role in security research.

July 1, 2026
AI's Dark Side Exposes Shipping's Cyber Readiness Gap as Training Lags Behind Digitalisation Technology

AI's Dark Side Exposes Shipping's Cyber Readiness Gap as Training Lags Behind Digitalisation

As shipping digitalises, cyber awareness training for seafarers has not kept pace, leaving vessels vulnerable to AI-powered attacks. Kris Vedat, CEO of SmartSea, argues for mandatory cyber security as part of STCW Basic Training and prioritisation by the IMO.

June 18, 2026