
Google released three Chrome updates that together closed 1,442 security vulnerabilities — more than the preceding 23 major Chrome milestones combined. The dramatic spike is driven by AI-powered flaw discovery: Google is using an agent harness built on its Gemini models to systematically scan Chrome’s source code, a technique that surfaced bugs that had been hiding in the codebase for over 13 years. Google’s own statistics note that the National Vulnerability Database recorded nearly 47,000 flaws across all software in 2026 so far, approaching the full-year total for 2025 — reflecting a broader industry acceleration in AI-assisted vulnerability research.
In response to what it calls “fast-moving, AI-powered attacks,” Google is also accelerating Chrome’s release cadence. The browser is moving to a two-week cycle for major milestones, with weekly security-only updates in between, and Google is piloting a shift to two security releases per week. The underlying message is that the window between a flaw being discovered and a patch reaching users needs to shrink, because attackers are increasingly using the same AI tooling to find and exploit those flaws first.
How to check if you’re affected
Affected versions include all Chrome releases before version 150. To verify and update:
- Open Chrome, click the three-dot menu → Help → About Google Chrome. The browser will check for updates and install the latest version automatically.
- A restart is required for the update to take effect.
- On Android, update Chrome through the Google Play Store; on iOS, through the App Store.
