AI Pulse by Inblix

AI found 1,072 Chrome bugs — including a 13-year-old sandbox escape

Ars Technica AI · Jul 30, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: AI found 1,072 Chrome bugs — including a 13-year-old sandbox escape

The volume of security fixes landing in Chrome has gone parabolic, and the culprit is Google’s own AI. The company just packed 1,072 bug fixes into two milestone releases — Chrome 149 and 150 — which is more than the previous 23 releases combined. That’s not a typo. Giant cybersecurity models are now probing the browser’s codebase at a speed no human team could match, and they’re dredging up horrors that have lurked in plain sight for over a decade.

One of those latent nightmares sat in Chrome’s code for 13 years. If exploited, it would have let an attacker punch through the browser’s celebrated sandbox and access local files. “Some of these vulnerabilities were serious,” a Google representative noted, in what might be the understatement of the year. The speed of AI-driven discovery is a double-edged sword, though. Google knows that if its own models can find flaws this fast, adversaries with similar tools can too. The race isn’t just to patch — it’s to patch before anyone else even knows the bug exists.

To shrink that window, Google is piloting a twice-weekly update cadence, accelerating the two-week cycle it just announced earlier in 2026. That means Chrome could soon push out patches every few days instead of every few weeks. The challenge isn’t just engineering velocity; it’s user experience. Nobody wants their browser to restart constantly, so Google says it’s working on ways to make these updates land without disrupting your workflow.

The unspoken story here is what this means for every software vendor. If Google’s AI scanners are turning up this much rot in Chrome — arguably the most aggressively hardened consumer application on the planet — what’s lurking in your VPN client, your PDF reader, or that enterprise tool your IT department deployed five years ago? The era of AI-driven vulnerability discovery has arrived. The era of AI-driven exploitation is right behind it.

💡 Key Takeaways

  1. AI-powered security analysis has increased Chrome’s bug fix volume so dramatically that two recent releases contained more fixes than the previous 23 combined.
  2. One vulnerability discovered by AI had been hiding in Chrome’s production code for 13 years and could have allowed attackers to bypass the browser’s sandbox entirely.
  3. Google is piloting a twice-weekly Chrome update cycle to outpace malicious actors who may use similar AI tools to exploit newly discovered flaws before patches ship.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles