Google Says AI Helped Chrome Teams Patch 1,072 Security Bugs in June
Two browser releases fixed more flaws than the previous 23 versions combined, changing the economics of vulnerability discovery.

Google says its internal AI tools helped engineers fix 1,072 security vulnerabilities across two Chrome versions released in June. That exceeds the 1,036 fixes recorded across the previous 23 versions, covering roughly two years of browser updates.
The increase supports a prediction security researchers have made since large language models became widely available: automated systems will discover flaws at a scale that forces defenders to automate triage and remediation. Chrome engineering director Doug Turner said tools including Gemini have changed the economics of vulnerability research by turning parts of discovery into an industrial process.
A larger patch count does not necessarily mean Chrome suddenly became less secure. It may indicate that Google can now find issues that previously remained hidden or were too expensive to investigate. The important questions are severity, whether fixes introduce regressions and how quickly users receive stable updates.
Microsoft reported a similar jump, patching a record 570 flaws in a recent monthly update and citing AI-supported work. Apple has not shown the same acceleration, according to independent tracking, although differences in disclosure, product scope and release practices make direct comparisons difficult.
The volume of fixes may create patch fatigue for enterprise administrators who cannot update every browser immediately. Google should provide clear severity ranking and stable deployment guidance so organizations can prioritize urgent vulnerabilities. Automated discovery creates value only when the downstream release process can absorb the additional work without leaving systems in a permanently incomplete state.
AI-assisted bug discovery can improve browser security, but it may also produce findings faster than maintainers and enterprise users can absorb patches. Google should publish enough technical detail for administrators to prioritize updates without giving attackers a simple recipe before adoption rises. Researchers will also want to know the false-positive rate and whether automated tools find deep logic flaws or mostly variations of familiar memory errors. The long-term measure is not the number of reports. It is the reduction in exploited vulnerabilities and the time between discovery, a stable fix and broad installation.
Attackers will use the same technology to search for weaknesses and generate exploit variations. Defenders therefore need systems that connect discovery to reproducible testing, code review and deployment. AI can increase the volume of candidate fixes, but humans remain responsible for deciding which changes are correct and for proving that a faster patching pipeline does not create a faster path to new failures.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



