Google announced on Thursday that it fixed 1,072 security bugs across the last two versions of its Chrome browser, both released in June 2026 — more than the 1,036 flaws patched in the previous 23 versions over the last two years combined. The company attributes this surge to its internal AI tools, including Gemini, which have automated the discovery of vulnerabilities at a scale that human teams could not achieve alone.
How AI is reshaping Chrome security
Google’s director of engineering for Chrome, Doug Turner, told TechCrunch that large language models have “fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation.” He added, “By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update.”
The data, published in a white paper by Google, shows an exponential increase in bug fixes starting with Chrome version 126, released in June 2024. The two most recent milestones — Chrome 149 and 150 — each fixed hundreds of security flaws, a stark contrast to earlier versions that typically addressed dozens.
Cybersecurity experts have long warned that AI-powered systems would find an exponentially growing number of bugs, forcing defenders to also adopt AI to stay ahead. This prediction is now backed by real data, with Google’s chart showing a steep upward curve in vulnerability detection.
Also read: Winamp taps Deezer to power its next-generation music player, targeting a 2027 launch
Industry-wide trend: Microsoft and Apple diverge
Google is not alone in this trend. Earlier this month, Microsoft announced it had patched a record 570 security flaws across its product lines in its June 2026 Patch Tuesday release. Microsoft also cited its own use of AI to explain the sudden jump in bug fixes, according to a company blog post.
Apple, however, does not appear to be registering the same exponential increase. An independent count of bugs fixed by Apple in 2026 totals 482, which is roughly on pace to equal or surpass the number of fixes from 2025 and is also roughly equal to the number of bugs Apple patched in 2015. TechCrunch reached out to Apple for comment but did not receive a response.
The divergence highlights a strategic difference: while Google and Microsoft are aggressively deploying AI for vulnerability discovery, Apple’s approach has not yet yielded a similar spike. Whether this reflects a different security philosophy or a lag in AI adoption remains unclear.
What this means for Chrome users and the broader web
For the roughly 3.5 billion Chrome users worldwide, the rapid pace of bug fixes means a more secure browsing experience. Vulnerabilities that might have remained undetected for months or years are now being found and patched within weeks. However, the same AI tools that help Google defend its browser could also be used by attackers to discover zero-day exploits faster, creating an arms race between defenders and adversaries.
Google’s white paper emphasizes that the company is investing heavily in AI-driven security to stay ahead of this threat. “We are preemptively fixing vulnerabilities, outpacing our adversaries,” Turner said. The next milestone, Chrome 151, is expected in July 2026, and if the trend continues, it may set another record for bug fixes.
Industry analysts are watching closely. If AI-driven vulnerability discovery becomes the new standard, the entire software industry may need to rethink its approach to patching and disclosure. For now, Google’s data provides the clearest evidence yet that the era of automated, large-scale cybersecurity is already here.