Google's Gemini based AI agents discovered and patched 1,072 security vulnerabilities across Chrome 149 and 150 in June 2026 — surpassing the 1,036 bugs fixed in the previous 23 major releases combined.

Create a landscape editorial hero image for this Studio Global article: What did Google announce about AI-powered Chrome security fixes, including the number of bugs patched in the two most recent releases, the r. Article summary: ## What Google Announced About AI-Powered Chrome Security. Topic tags: general, general web, documentation, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
On July 30, 2026, Google published a major security update detailing a sweeping transformation of Chrome's security posture driven by AI . The results are dramatic: AI agents are finding and fixing more bugs in a single month than the Chrome team previously fixed in two years — and they're uncovering vulnerabilities that have evaded human reviewers for over a decade.
Chrome 149 and Chrome 150, both released in June 2026, fixed a combined 1,072 security bugs — more than the 1,036 bugs fixed across the prior 23 major releases (roughly two years) combined . This represented the highest patch volume in Chrome's history for a single-month period, driven almost entirely by internal AI tools rather than external researcher submissions
.
Google credited internal AI models — specifically Gemini-based agents — for automating nearly every stage of the vulnerability lifecycle . The AI tools:
In early 2026, Google built an agent harness using Gemini that found vulnerabilities with "higher efficiency and lower false positives" than prior methods . Separately, DeepMind released Gemini 3.5 Flash Cyber on July 21, 2026, a specialized model for discovering, validating, and patching vulnerabilities
. Google had also previously launched CodeMender in October 2025, an AI agent that automatically detects, patches, and rewrites vulnerable code
. The company now uses multi-agent workflows where AI agents automatically triage issues, draft candidate code fixes, serve as critics, and write cross-platform tests
.
One of the most striking findings was a sandbox escape vulnerability that had quietly existed in Chrome's codebase for more than 13 years . The bug, identified as CVE-2026-15119, was a race condition in the GetUserMedia implementation that would have allowed a compromised renderer process to escape the sandbox and trick the browser into reading local files
. Google noted that the Gemini-based AI agent discovered this flaw — a bug that had evaded all prior human code review for over a decade
. For many on the Chrome security team, this moment "cemented the potential of AI-powered vulnerability detection"
.
Sandbox escapes are among the most dangerous browser vulnerabilities because they allow an attacker who has already compromised the renderer process to break out of the restricted environment and execute code on the user's system. Previous sandbox escapes, such as CVE-2025-4609, earned researchers $250,000 bug bounties .
Google announced several changes to Chrome's release cadence to keep pace with the AI-driven discovery rate:
Google acknowledged that frequent updates requiring a browser restart create a significant user burden. The company is investing in "dynamic patching" (also called "dynamic matching") to replace background child processes (like the Renderer and GPU) with updated binaries on the fly, eliminating the need for a full browser restart in most cases . Starting with Chrome 150 on macOS, the browser can also automatically restart to apply a pending update when it is running in the background without any open windows
.
On July 29, 2026, Google released Chrome 151 Stable (version 151.0.7922.71/.72 for Windows/macOS, 151.0.7922.71 for Linux), fixing 370 security vulnerabilities . The severity breakdown:
| Severity | Count |
|---|---|
| Critical | 7 |
| High | 71 |
| Medium | 170 |
| Low | 122 |
The seven critical vulnerabilities included:
Chrome 151 also transitioned its XML parsing engine to a memory-safe Rust implementation for common scenarios where XSLT is not required, eliminating potential memory corruption bugs while maintaining full compatibility with web specifications .
You don't need to do anything special — Chrome updates automatically in the background. But the pace of updates is about to accelerate significantly. Starting September 8, 2026 with Chrome 153, major releases will arrive every two weeks instead of every four . The rollout of dynamic patching means fewer disruptive browser restarts even as updates become more frequent.
The security patch landscape across the industry reached unprecedented volume in mid-2026. Chrome's AI-driven approach represents perhaps the most dramatic example of how AI tools are transforming vulnerability discovery and remediation at scale . Doug Turner, Chrome's director of engineering, told TechCrunch that LLMs have "fundamentally shifted the economics of cybersecurity"
.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Google's Gemini based AI agents discovered and patched 1,072 security vulnerabilities across Chrome 149 and 150 in June 2026 — surpassing the 1,036 bugs fixed in the previous 23 major releases combined.