Google's Chrome fixed 1,072 bugs in AI-assisted milestone push
TL;DR
- Chrome 149 and 150 combined fixed 1,072 security bugs, more than the prior 23 milestones combined, per Google's Chrome Security Team.
- In May, Google says its security tooling blocked over 20 vulnerabilities from reaching production, including one rated critical S1+.
- AI agents Big Sleep, Naptime, and CodeMender helped surface a sandbox-escape bug that had lived in Chrome's codebase for more than 13 years.
A quiet number tucked into Google's latest Chrome security update is worth sitting with. In Chrome 149 and 150 combined, the team says it fixed 1,072 security bugs, more than the total across the prior 23 milestones put together. That is the headline claim from a post on the Google blog attributed to the Chrome Security Team, and the reason they give for the step change is AI.
The tools they name are Big Sleep, Naptime, and CodeMender, AI agents pointed at Chromium's own code. In one striking example, the post says the effort surfaced a sandbox escape vulnerability that had quietly survived in the codebase for more than 13 years. In May alone, integrated security tooling blocked over 20 vulnerabilities from reaching production, including one rated critical S1+.
The reason this matters beyond Google is downstream. Chromium ships with more than 2,300 third-party dependencies across satellite projects like V8, BoringSSL, Skia, ANGLE, and Dawn, and any Chromium-based browser or embedded engine inherits both the fixes and the pressure to ship them fast. Google also says 97% of first-party Chrome code now compiles cleanly with strict unsafe-buffer warnings, a real memory-safety milestone if the number holds up under independent scrutiny.
The honest caveat is what the post does not tell you. It does not break out how many of those 1,072 bugs were AI-found versus human-triaged, what the false-positive rate on Big Sleep and Naptime looks like, or how much of the surge is a backlog being burned down rather than a new steady state. Take the specifics as reported by Google, not as independently verified.
The upside, if the trend line is real, is that browser security starts to look less like a heroic scramble after each zero-day and more like a continuous process quiet enough that most users only notice through faster restarts. Google joining a $12.5 million donation to the Alpha-Omega project is a small signal that some of this tooling posture is meant to spread beyond Chrome, which is where it would matter most.
Shared on Bluesky by 2 AI experts
-
a bunch of this blog is about the project my wife Elly is the tech lead of!!!! I'm so proud of her! blog.google/security/chr...
View on Bluesky →
Originally reported by blog.google
Read the original article →Original headline: Stronger with every update: How we’re making Chrome and the web safer in the AI Era