SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Security

Google fixed 1,072 Chrome bugs in one month using AI

In June 2026, Google fixed more Chrome security bugs than in the previous two years. AI tools turned vulnerability detection into an industrial process.

Automush
Published 31.07.2026
What this means for your business

If you build systems or develop software, assume you will find vulnerabilities 10 times faster than before – and so will adversaries. Move now to embed AI-powered automated security scans in your development pipeline, and build a process that handles security updates in days, not weeks. If you rely on an external vendor, verify they have automatic update policies and ask how long passes between discovery and fix.

In June 2026, Google fixed 1,072 security bugs in two Chrome releases, more than the 1,036 fixes it made in the previous 23 releases over two years. The surge came from using internal AI tools like Gemini. Microsoft reported a similar pattern with 570 security fixes in the same month.

What actually happened

Doug Turner, Chrome’s engineering director, said LLMs fundamentally changed the economics of cybersecurity and turned vulnerability discovery into an automated operation at industrial scale. Google used large models to scan Chrome’s source code and identify vulnerable code patterns.

The exponential jump: over two years they fixed 1,036 bugs in 23 releases, and in one month they fixed 1,072 in just two releases. This is not incremental improvement, it is an order-of-magnitude shift.

Why it matters beyond the headline

The threat landscape has changed. If Google and Microsoft are finding vulnerabilities 10 times faster, attackers are doing the same. An organisation building a system in Israel under regulatory standards must assume the window between discovery and exploitation has shrunk dramatically.

This changes three things in architecture: first, you cannot rely on “security through obscurity” – the assumption that internal code will not be examined. Second, the security update cycle must be automatic and fast, not a manual quarterly process. Third, architecture must assume breach and build internal separations.

Bottom line: those not using AI for defence are falling behind while their adversaries accelerate.

What to do this week

If you are building a system: embed AI-powered static security scanning tools in your CI/CD pipeline. There are open-source and commercial tools that use LLMs to identify vulnerabilities before production. Verify you have a process to update critical dependencies within 48 hours of a fix being published.

If you work with a vendor: ask them how long passes between vulnerability discovery and fix deployment to customers, and whether they have automatic security updates. If the answer is “we send a notice and you schedule an upgrade,” that is no longer sufficient.

If you are building internal automations that connect to external systems, read about secure AI agent architecture that assumes every connection point could be breached.

Sources

Frequently asked

Does a small business need to invest in AI security tools?

Not necessarily. A small business mainly needs to ensure it works with cloud and software vendors who already use these tools and update automatically. The critical investment is in a fast update process, not the scanning tool itself.

How long does it take to implement automated security scanning in development?

Basic integration of a static scanning tool into a CI/CD pipeline typically takes one working day. The real time is in calibrating alerts to reduce false positives and building a fast fix process, which takes two weeks to a month.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.