How Google used AI agents to find and fix 1,072 Chrome security bugs – in 60 days
What happened
Google deployed AI agents powered by its Gemini model to hunt down and fix 1,072 security bugs in the Chrome browser over just 60 days. These AI agents simulated attacker behavior and analyzed code to proactively identify vulnerabilities before they could be exploited. Chrome’s user base of 3.5 billion devices represents a massive attack surface that demands rapid vulnerability management. Using automation at this scale sped up discovery and patching significantly compared to traditional manual security audits.
Why it matters
Chrome is one of the most widely used browsers globally, making its security critical to internet health and user safety. Manually finding and fixing over a thousand bugs in two months would be nearly impossible with human teams alone. By automating this process, Google pressures attackers by reducing the window of opportunity to exploit vulnerabilities. It also lowers operational costs and frees up security engineers to focus on complex investigations. This approach raises the bar on how quickly large software projects can close security gaps.
What to watch next
Other major software vendors will likely test AI agents for vulnerability hunting, pushing AI-driven security into mainstream practice. Watch for announcements from cloud providers and open source projects adopting automated bug detection at scale. The quality and speed of AI vulnerability discovery will influence how companies allocate security budgets and staffing. Regulators and enterprise customers may start demanding evidence of AI-enhanced security practices to ensure software safety. Close attention to how these AI tools handle false positives and code complexity will also shape adoption.
AI Quick Briefs Editorial Desk