# Google's AI Security Machine Just Dug Up a 13-Year-Old Chrome Bug — and That's the Least of It


A Chrome vulnerability that had been hiding in plain sight since 2013 finally got pulled into the light last quarter. Not by a researcher burning the midnight oil, not by a bug bounty hunter with a clever fuzzing setup — by an AI agent that Google unleashed on its own codebase.


The flaw was a sandbox escape: if an attacker had already compromised a renderer process, this vulnerability would have let them read local files off a user's machine. Thirteen years. Multiple security audits. Countless fuzz runs. And it took a large language model to surface it.


That detail sits at the center of something genuinely historic happening in Chrome's security engineering right now.


## The Numbers That Demand Context


Chrome 149 and 150 fixed 1,072 security vulnerabilities. Together. Two releases. That figure alone is staggering enough, but Google adds the context that makes it land: those two milestones fixed more bugs than the previous *twenty-three* Chrome releases combined.


This is not incremental improvement. It's a phase change.


Google has been building toward this since 2023, when it started integrating large language models into its fuzzing pipelines. That led to Project Zero's Naptime framework, which gave AI models specialized vulnerability research tooling. Naptime evolved into Big Sleep — a collaboration with Google DeepMind that operated as a true vulnerability discovery agent and began finding real flaws in Chrome's V8 engine and graphics stack. By early 2026, Google had a Gemini-powered agent harness running across the broader Chrome codebase, specifically tuned to reduce the false-positive rate that plagues automated security tooling.


The result is an end-to-end AI pipeline: discovery, reproduction, severity rating, developer assignment, candidate patch generation, test creation. Humans still make the final calls, but the system is doing the heavy lifting that used to eat security engineers alive.


## What "Automated Triage" Actually Means in Practice


The vulnerability reward program tells a secondary story worth paying attention to. By March 2026, Google had already received more external bug reports than it did in all of 2025. The VRP is being flooded — partly because researchers are using their own AI tools to hunt bugs, partly because awareness of Chrome's attack surface has grown, and partly because the program's historical payouts make it worth the effort.


Google's response: automate the intake. The system now filters spam and duplicates, reproduces proof-of-concept exploits, assigns severity ratings, and routes reports to the right developers. Google estimates this saves hundreds of hours of engineering time per month. Perhaps more tellingly, the company modified the VRP to explicitly prioritize reports that go beyond what automated tooling is already finding. Translation: if your bug is in a class of flaws the AI already catches, your report gets deprioritized. The bar for human researchers just shifted.


In May, before any of this reached production, the AI systems intercepted more than 20 vulnerabilities — including one rated critical. Stopped before shipping. That's the kind of number that gets CISO attention.


## The Patch-Gap Problem Gets Harder


Here's the friction point that Google is now running into at speed: finding and fixing vulnerabilities faster also means publishing patches faster — and Chrome's source code is public.


The moment a security fix lands in Chrome's repository, sophisticated attackers can inspect the diff and reverse-engineer what was broken. That window between commit and user update is known as the patch gap, and historically it's been measured in weeks. At the current rate of vulnerability discovery and patching, Google is compressing both sides of that equation simultaneously — more patches, arriving faster, with attackers watching every commit.


Google's countermoves: a two-week major release cycle, weekly security updates, and an experimental two-releases-per-week security channel. It's also developing "dynamic patching" — the ability to apply updates without requiring the user to restart the browser. Chrome 150 on macOS is already doing something close: if the browser is running in the background with no open windows, it can now auto-restart to absorb pending updates.


The long-term vision is continuous, invisible updating. Chrome becomes less like installed software and more like a streaming service that's always on the latest version without asking.


## HackWire Analysis


The 1,072 bug number is impressive. The 13-year-old sandbox escape is the actual story.


What that vulnerability represents is a class of problem that traditional security tooling — including fuzzing, which Google correctly notes still finds complex bugs that AI misses — was structurally unable to surface. Fuzzers find crashes. Code review finds obvious mistakes. What they struggle with is semantic understanding of trust boundaries: who is supposed to be able to read what, and under what assumptions? That's exactly the kind of reasoning LLMs are surprisingly well-suited for, especially when you give them context about threat models and trust hierarchies (which is why Google is now encouraging developers to write SECURITY.md files — the AI needs to know what "secure behavior" looks like to recognize deviations from it).


The deeper implication is uncomfortable: if a 13-year-old bug was sitting in one of the most heavily audited codebases on earth, how many are sitting in codebases with *fewer* resources? Chrome has a dedicated security team, Project Zero, an active VRP, and now a fleet of AI agents. The average enterprise application has none of those. The gap in defensive AI investment between Google-scale organizations and everyone else is widening, not closing.


There's also a race dynamic worth watching. Google is explicit that its automated systems are not replacing human researchers — they're handling volume so humans can focus on depth. But the same tools are available to threat actors. The patch-gap acceleration cuts both ways: faster fixes, but also a higher-velocity target environment where attackers with similar tooling can turn a public commit into a working exploit faster than ever. Google's dynamic patching initiative is the right answer, but it's a countermeasure to a problem that its own AI-driven fix velocity is partly creating.


The field of browser security is about to look very different. The question for defenders in other industries isn't whether AI will eventually reach their toolchains — it's whether they'll build that capability before adversaries build the corresponding offense.


— HackWire Editorial


---


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)