Editorial illustration for Chrome Will Patch Twice Weekly After AI Finds More Bugs
Chrome Patches 1,072 Bugs in June With AI Help
Chrome Will Patch Twice Weekly After AI Finds More Bugs
Google shipped fixes for 1,072 security bugs in Chrome's two major releases in June, more than the previous 23 releases combined, according to a report the Chrome security team published Thursday. That's not a typo. It's the clearest sign yet that AI-assisted vulnerability hunting has changed the math on how fast browser makers need to move.
Chrome was the first major browser to push automatic updates, and a decade ago its six-week patch cycle drew criticism as too aggressive. Six weeks now sounds almost leisurely. The team is already shifting toward releasing a major version every two weeks, layered with additional security patches on a weekly basis, a cadence that would have seemed unmanageable a few years back.
Some of the bug reports still come from outside researchers submitting findings the old-fashioned way. But Google says the real driver behind the June spike is internal: AI tools now baked into how Chrome engineers find, sort, and fix flaws before anyone outside the company even notices them. Chrome's Parisa Tabriz, the browser's vice president and general manager, has watched that shift unfold from the inside.
Chrome is already moving toward a new normal of pushing out a major release every two weeks with additional weekly security updates. But the frenzy of vulnerability discoveries has been so intense, and the team has had so much success incorporating new AI models and capabilities into the workflow of finding and fixing new bugs, that for now the group is piloting a cadence of releasing security fixes twice a week.
Why this matters
Twice-weekly patching from Chrome is a small operational detail with a big signal buried in it: the bug-finding side of AI is outpacing the bug-fixing side, and Google is one of the few outfits with the engineering muscle to even attempt keeping up. Doug Turner's own hedge, "who knows," is telling. Chrome's team isn't claiming mastery over this shift, just reacting to a volume problem AI created faster than expected.
For developers and founders building on top of Chromium, or any widely used dependency, the lesson is that AI-assisted vulnerability hunting is going to surface flaws in your stack whether or not you have Google's release cadence to absorb them. Six weeks used to be the industry benchmark for "fast." That number is now obsolete, and there's no guarantee twice a week holds either. If you're maintaining software with any real user base, this is worth watching closely: the tooling that finds these bugs is improving faster than most teams' patch pipelines, and Chrome just admitted it's struggling to keep pace itself.
Common Questions Answered
How many security bugs did Google fix in Chrome's two major releases in June?
Google shipped fixes for 1,072 security bugs in Chrome's two major releases in June, which is more than the previous 23 releases combined. This dramatic increase represents a significant shift in the volume of vulnerabilities being discovered and patched.
Why is Chrome moving to twice-weekly security patch releases?
Chrome is adopting twice-weekly security patch releases because AI-assisted vulnerability hunting has dramatically increased the number of bugs being discovered. The team has had such success incorporating new AI models into their bug-finding workflow that the volume of vulnerabilities now outpaces their ability to fix them at the previous pace.
What was Chrome's patch cycle like a decade ago compared to today?
A decade ago, Chrome's six-week patch cycle was considered aggressive and drew criticism for moving too fast. Today, Chrome is piloting twice-weekly security updates with major releases every two weeks, demonstrating how dramatically AI-assisted vulnerability discovery has accelerated the need for faster patching.
What does the shift to twice-weekly patching reveal about AI's impact on cybersecurity?
The twice-weekly patching schedule signals that the bug-finding side of AI is outpacing the bug-fixing side, creating a volume problem that even well-resourced companies like Google struggle to keep up with. This indicates that AI has fundamentally changed the mathematics of how fast browser makers need to operate to maintain security.
Further Reading
- Stronger with every update: How we’re making Chrome and the web safer in the AI Era - Google Security Blog
- Google says AI helped Chrome fix 1,072 security bugs in two releases - BleepingComputer
- Chrome may get faster updates with no restart required - Ars Technica
- Google wants to update Chrome without a full browser restart - 9to5Google
- Google is rebuilding Chrome security using AI to catch hidden vulnerabilities - Android Authority