# Google's AI Dug Up a 13-Year-Old Chrome Sandbox Escape — and 1,800 More Bugs This Year


## The Threat


Chrome has always been a high-value target, but 2026 has exposed just how much attack surface was quietly accumulating in the browser. Google this week confirmed what security researchers had been speculating about since April: the dramatic surge in Chrome CVEs — over 1,800 bugs patched so far this year — is the direct result of deploying AI-driven vulnerability discovery at scale.


The most striking data point isn't the raw count. It's a single bug: CVE-2026-3545, a critical sandbox escape that had been sitting in Chrome's Navigation component for 13 years. The flaw allowed a compromised renderer to manipulate the browser into reading arbitrary local files by processing a crafted HTML page. That's not an edge case. That's a clean, exploitable primitive that could have been chained with any renderer-level compromise to break Chrome's foundational isolation guarantee — and it was invisible to all prior security review.


Google's Gemini-based agent harness, built in early 2026, found it. The system is trained on Chrome's entire Git history and a corpus of previously identified CVEs, runs vulnerability-finding models over the codebase in multiple passes, and uses a "critic" agent that ingests developer-supplied SECURITY.md files to validate findings. It's not a static analyzer bolted onto CI — it's an active, iterative hunting loop that can probe the same code from different angles. That architectural difference appears to matter enormously: Chrome 149 and 150 alone patched 1,072 vulnerabilities, exceeding the total fixed across the prior 23 releases combined.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-3545 |

| CVSS Score | 9.8 (Critical) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |

| CWE | CWE-20 — Improper Input Validation |

| Attack Complexity | Low |

| Authentication Required | None |

| Impact | Sandbox escape; local file read by compromised renderer |

| Patched | Chrome 145 (early May 2026) |

| Discovery Method | Google Gemini-based AI agent harness |


## Affected Products


  • Google Chrome — all versions prior to 145 (CVE-2026-3545)
  • Google Chrome — all versions prior to 149/150 (additional 1,072 vulnerabilities)
  • Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi) that have not yet rebased to affected patch levels should be assessed independently

  • ## Mitigations


    Update immediately. Chrome 145 is the minimum for CVE-2026-3545 remediation; Chrome 150 addresses the broader set of AI-discovered vulnerabilities.


    For organizations managing Chrome deployments:


  • Enforce Chrome update policies via Google Admin Console or MDM. Do not rely on user-initiated restarts.
  • Monitor for Chrome version compliance across endpoints — given the 9.8 CVSS score, stragglers in your fleet are a meaningful risk.
  • If you use Chromium-based enterprise browsers (Edge, etc.), verify the vendor's equivalent patch status independently.
  • Consider enabling Chrome's twice-a-week security release cadence (currently in pilot) for high-risk environments once it reaches general availability.

  • For security teams tracking exposure:


  • Audit browser versions in your EDR or asset inventory now. CVE-2026-3545 is exactly the kind of silent critical that gets missed in patch reporting because it predates most vulnerability tracking workflows.
  • Watch for dynamic patching support in future Chrome releases — Google is building update delivery that won't require a browser restart, which will materially reduce enterprise patch lag.

  • No workarounds exist for CVE-2026-3545. The only fix is updating to Chrome 145 or later.


    ## References


  • [Google Chrome Releases blog — Chrome 150](https://chromereleases.googleblog.com/)
  • [Google Security Blog — AI-powered vulnerability discovery](https://security.googleblog.com/)
  • [NVD entry for CVE-2026-3545](https://nvd.nist.gov/vuln/detail/CVE-2026-3545)
  • [Google Vulnerability Reward Program](https://bughunters.google.com/)
  • [Original SecurityWeek coverage](https://www.securityweek.com/)

  • ---


    ## HackWire Analysis


    The 13-year lifespan of CVE-2026-3545 is the real story here, and it deserves more attention than the AI narrative that Google is (reasonably) leading with. This wasn't an obscure code path in an experimental feature — it was in Chrome's Navigation component, one of the most heavily reviewed parts of the browser. Thousands of audits, fuzzing campaigns, and VRP submissions missed it for over a decade. An AI system found it in a matter of months.


    That should unsettle anyone who assumed modern security review processes were approaching saturation on browser attack surface. They weren't. And if Google's own, exceptionally well-resourced security team had this gap, it's fair to ask what comparable blind spots exist in browsers with smaller security investment — or in the vast landscape of Electron apps built on Chromium that inherit its vulnerabilities without Google's patching infrastructure.


    The operational implications are equally significant. Google is now piloting twice-weekly security releases, automating CVE description generation, and building dynamic patching that eliminates restart requirements. These aren't nice-to-haves — they're direct responses to a new reality where the vulnerability discovery rate has outpaced traditional release and disclosure workflows. When your AI is finding bugs faster than humans can write advisories, you rebuild the pipeline.


    For defenders, the immediate action is straightforward: patch. But the strategic takeaway is harder. If an AI agent harness scanning Chrome's Git history can surface 1,800+ previously unknown vulnerabilities in months, the same technique applied to other long-lived codebases — operating system kernels, network device firmware, authentication libraries — will yield comparable results. The vulnerability backlog across the industry is almost certainly much larger than current CVE counts suggest. Security teams should be planning now for a world where AI dramatically accelerates the pace at which known-unknown risks become known-exploitable.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)