New Delhi: Google has said artificial intelligence is now embedded across the security workflow for Google Chrome, helping engineers identify, prioritise and fix software vulnerabilities faster while accelerating browser updates.
The company said large language models have been supporting Chrome’s security programme for several years and are now being used throughout the process, from detecting vulnerabilities in the browser’s codebase to validating reports, generating candidate fixes and creating tests before engineers approve changes.
According to Google, AI recently identified a sandbox escape vulnerability that had remained hidden in Chrome’s code for more than 13 years, highlighting its ability to uncover long-standing security flaws.
The company said AI also automates several stages of vulnerability triage by filtering duplicate and invalid reports, reproducing bugs, assigning severity levels and routing issues to engineering teams. These capabilities are estimated to save developers hundreds of hours each month while reducing false positives.
Google said AI-assisted development has significantly accelerated security fixes. Chrome 149 and Chrome 150 together resolved 1,072 security bugs, surpassing the total number of vulnerabilities fixed across the previous 23 Chrome stable releases combined.
The company added that AI tools integrated into Chrome’s continuous integration system prevented more than 20 vulnerabilities from reaching production during May alone, including one classified as critical.
Alongside AI-driven development, Google is speeding up Chrome’s security update cycle. The browser is moving to a two-week milestone release schedule with weekly security updates, while the company is also testing two dedicated security releases each week.
Google is also developing dynamic patching, a feature designed to apply many security updates without requiring users to restart the browser, reducing disruption while improving protection.
Beyond AI, the company said it is expanding memory safety protections in C++, increasing the use of Rust in Chrome’s codebase, deploying AI to identify vulnerabilities before code is submitted and automating updates for third-party software dependencies.
The latest efforts reflect Google’s broader push to integrate AI into software security, with the company betting that automation can help reduce the time between identifying vulnerabilities and delivering protections to users.