Google patched over 1,000 Chrome bugs in two releases using AI — more than the previous 23 milestones combined
Google says large language models now handle nearly every stage of Chrome's vulnerability management pipeline, from discovery to patch generation.
Key points
Google patched 1,072 security bugs across Chrome 149 and 150, exceeding the total fixed in the previous 23 Chrome milestones combined.
LLMs are now used across Chrome's entire vulnerability management pipeline: discovery, reproduction, severity assessment, developer assignment, patch generation, and test creation.
Google's AI security tooling evolved from LLM-assisted fuzzing (2023) to Project Zero's Naptime, then Big Sleep with DeepMind, and a Gemini-powered agent harness in early 2026.
Security advisory
CVE:
CVE-2026-15903
Severity:
High
Affected:
Google Chrome desktop versions prior to 150.0.7871.128; Chromium-based browsers embedding the affected V8 engine; all operating systems (Windows, macOS, Linux) shipping vulnerable Chrome versions
Patch status:
Patched in Chrome 150.0.7871.128
3 sources 2 web 88% confidence
Source highlights
SourceRoleHeadlinePublishedMatch
TechCrunchPrimaryGoogle says it fixed more Chrome bugs in June than over the past two years, thanks to AI80%
bleepingcomputer.comWeb contextGoogle says AI helped Chrome fix 1,072 security bugs in two releases—64%
sentinelone.comWeb contextCVE-2026-15903: Google Chrome V8 RCE Vulnerability—48%