Google 喺 2026 年 7 月 30 日發布咗一份重要安全報告,詳細講述點樣用 AI 嚟改造 Chrome 嘅安全防護 Chrome 149 同 150 喺 2026 年 6 月總共修復咗 1,072 個安全漏洞,呢個數字比之前 23 個主要版本(大約兩年)加埋嘅 1,036 個仲要多 Google 歸功於自家嘅 Gemini 模型,話佢哋已經可以自動發現漏洞、分類報告、生成修補程式、甚至審查程式碼修改

Create a landscape editorial hero image for this Studio Global article: What did Google announce about AI-powered Chrome security fixes, including the number of bugs patched in the two most recent releases, the r. Article summary: ## What Google Announced About AI-Powered Chrome Security. Topic tags: general, general web, documentation, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
Google 喺 2026 年 7 月 30 日發表咗一份題為「Stronger with every update: How we're making Chrome and the web safer in the AI Era」嘅重要安全更新報告,詳細講述佢哋點樣全面用人工智能嚟改造 Chrome 瀏覽器嘅安全防護機制 。
喺 2026 年 6 月推出嘅 Chrome 149 同 Chrome 150,總共修復咗 1,072 個安全漏洞——呢個數字比之前 23 個主要版本(大約兩年時間)加埋嘅 1,036 個漏洞仲要多 。呢個係 Chrome 歷史上單一個月最高嘅修復數量。
Google 將呢個成就歸功於內部嘅 AI 模型,特別係 Gemini 模型。佢哋已經可以利用 AI 自動化執行漏洞生命周期嘅幾乎每一個階段 :
喺 2026 年初,Google 用 Gemini 建立咗一個 Agent 系統,發現漏洞嘅效率同準確率都比以前嘅方法更高 。另外,DeepMind 喺 2026 年 7 月 21 日推出咗 Gemini 3.5 Flash Cyber,呢個係專門用嚟發現、驗證同修補漏洞嘅 AI 模型
。Google 之前亦已經喺 2025 年 10 月推出過 CodeMender,一個可以自動偵測、修補同改寫有問題程式碼嘅 AI Agent
。
其中一個最令人驚訝嘅發現係一個 sandbox escape 漏洞,呢個 bug 喺 Chrome 嘅原始碼入面靜靜地存在咗 超過 13 年 。呢個漏洞嘅編號係 CVE-2026-15119,係一個喺 GetUserMedia 功能入面嘅 race condition 問題。如果攻擊者成功利用呢個漏洞,就可以喺已經攻陷瀏覽器 renderer 程序嘅情況下,逃離沙箱保護,呃個瀏覽器讀取本地檔案
。Google 指出,係 Gemini AI Agent 發現咗呢個漏洞——一個喺過去十幾年都成功避過所有人類程式碼審查嘅 bug
。
為咗配合 AI 帶嚟嘅漏洞發現速度,Google 宣布咗幾項 Chrome 發布週期嘅改動:
Google 知道太頻密更新,每次都要 restart 瀏覽器,對用戶嚟講好麻煩。所以佢哋正投資開發 「動態修補」(又叫做「dynamic matching」)技術,可以 喺背景直接替換 Renderer 同 GPU 呢啲子程序嘅更新檔案,大部分情況下都唔使成個瀏覽器 restart 。不過呢個功能仍在開發階段,未正式推出。
喺 2026 年 7 月 29 日,Google 推出咗 Chrome 151 Stable(版本 151.0.7922.71/.72 for Windows/macOS,151.0.7922.71 for Linux),修復咗 370 個安全漏洞 。嚴重程度分布如下:
| 嚴重程度 | 數量 |
|---|---|
| Critical | 7 |
| High | 71 |
| Medium | 170 |
| Low | 122 |
七個 Critical 漏洞包括 Compositing 嘅 Use-after-free 問題(CVE-2026-17650)、輸入驗證不足問題,以及其他核心元件嘅記憶體損毀 bug 。Chrome 151 亦將佢嘅 XML 解析引擎轉用 記憶體安全嘅 Rust 語言實作,適用於唔需要 XSLT 嘅常見情況
。
雖然我哋未能完全核實你提及其他公司嘅具體數字(Microsoft 破紀錄嘅 Patch Tuesday、Apple iOS 26.6 嘅安全修復、Adobe 嘅 Chrome extension 修補、Oracle 喺 7 月嘅 1,449 個安全修補等等),但呢啲都話俾我哋知一個大趨勢:2026 年中嘅網絡安全修補數量已經達到前所未有嘅水平,而 Chrome 呢個 AI 驅動嘅做法,可以話係 AI 工具大規模改變漏洞發現同修復流程嘅最佳例子 。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Google 喺 2026 年 7 月 30 日發布咗一份重要安全報告,詳細講述點樣用 AI 嚟改造 Chrome 嘅安全防護
Google 喺 2026 年 7 月 30 日發布咗一份重要安全報告,詳細講述點樣用 AI 嚟改造 Chrome 嘅安全防護 Chrome 149 同 150 喺 2026 年 6 月總共修復咗 1,072 個安全漏洞,呢個數字比之前 23 個主要版本(大約兩年)加埋嘅 1,036 個仲要多
Google 歸功於自家嘅 Gemini 模型,話佢哋已經可以自動發現漏洞、分類報告、生成修補程式、甚至審查程式碼修改