Brief IA

Google and AI: 1,072 Chrome Bugs Fixed in 60 Days

🛠️ AI Tools·Tom Levy·

Google and AI: 1,072 Chrome Bugs Fixed in 60 Days

Google and AI: 1,072 Chrome Bugs Fixed in 60 Days
Key Takeaways
1Google used AI to identify and fix 1,072 security vulnerabilities in Chrome in just 60 days.
2The Gemini tool detected a ten-year-old vulnerability that had eluded human developers.
3Google's AI process saves hundreds of development hours each month.
💡Why it mattersThe speed of fixing vulnerabilities is crucial for the security of 3.5 billion Chrome users worldwide.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

With an impressive 3.5 billion active users, Google has the colossal responsibility of securing its Chrome browser. To achieve this, the company relies on a powerful tool, Gemini, which uses artificial intelligence to quickly identify security vulnerabilities before they can be exploited by malicious actors. Notably, AI has managed to discover a vulnerability in Chrome that had gone unnoticed for ten years, an exploit that human developers had repeatedly missed.

The Stakes of Security for Chrome

Chrome, along with its open-source project Chromium, ranks among the most complex open-source projects in the world. With a market share of around 73%, Chrome is used by 3.5 billion people, a figure that far exceeds the total population of the United States. This situation places Chrome developers under immense responsibility: a single unpatched vulnerability could potentially affect the security of billions of users. Google takes this mission very seriously, as evidenced by a recent blog post from the Chrome security team, which explains how AI is used to improve the detection, classification, and remediation of vulnerabilities.

A Rapid Increase in Fixes

Google has introduced "milestones," regular updates that occur approximately once a month. Milestone 128, released on August 20, 2024, marked the beginning of a series of bug fixes. Initially, each milestone allowed for the correction of about 50 bugs. However, this number quickly increased: milestone M146 saw 80 bugs fixed, M147 addressed 130, and M148 resolved 350 bugs. This exponential progression culminated with milestones M149 and M150, where 1,072 bugs were fixed, surpassing the total fixes of the previous 23 milestones combined.

The Implications of Such a Pace

The logistics behind these updates are impressive. Google releases major new versions every month, which involves a potential risk of global disruptions if a serious bug were to be inadvertently introduced. For each bug addressed, Google must validate the issue, fix it, conduct rigorous testing to ensure it does not interfere with billions of web pages and numerous Chrome extensions, publish a patch, and encourage users to update their browser.

The Integration of AI into the Process

Since 2023, Google has integrated AI tools to enhance security testing coverage, using unexpected and random inputs. In 2024, at the time of milestone M128, Google began using specialized AI tools for vulnerability analysis. In 2025, Google collaborated with DeepMind and Project Zero to develop Big Sleep, an agent capable of detecting bugs in the V8 JavaScript engine and the graphics stack. In 2026, Google introduced an agentic harness based on Gemini, designed to identify vulnerabilities throughout the entire Chrome codebase. This process is complex, akin to a game of chess where AI anticipates thousands of moves in advance.

A Race Against Time

Speed is essential, as billions of people depend on these fixes. Google has implemented a four-step triage process to efficiently manage bug reports:

  • Step 1: AI agents filter out incorrect, duplicate, or non-security-related vulnerability reports in Chrome.
  • Step 2: AI agents reproduce the bugs in virtual environments corresponding to the reported browser and operating system.
  • Step 3: Agents enrich the reports with metadata.
  • Step 4: Agents identify the appropriate human owner to investigate the bug.

Google estimates that this process saves hundreds of development hours each month.

An Urgent Need for Updates

There is a lag between the discovery of bugs by attackers and the release of fixes. Even when Google is aware of a bug, it often takes weeks for the fix to reach the stable channel of Chrome. Google aims to reduce this delay to two weeks for major milestones and to publish weekly security updates. In light of the accelerating attacks, Chrome is even considering doubling the frequency of security updates each week.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.