Imagine a hidden bug lurking in software for 13 years, quietly waiting to be discovered. Google's AI system, powered by its Gemini model, just uncovered such a vulnerability inside Chrome’s code dating back to 2013. This isn't any minor glitch. It's a serious sandbox escape flaw with a severity score of 9.8 out of 10, meaning attackers could break out of Chrome's secure environment and access users’ operating systems.
The bug was fixed recently in Chrome version 145, released in May 2026, but it took an AI agent to unearth it. This smart system combs through historical CVE data and Git commits, analyzing old and new code alike in isolated environments to find hidden weaknesses. Google stresses that the AI doesn't replace humans or fuzzing techniques but works alongside them. In fact, the number of vulnerability reports from external researchers has increased, leading Chrome’s team to adjust its reward program to encourage more submissions.
2026 is shaping up to be a record year for Chrome security. The combined releases of versions 149 and 150 alone patched 1,072 security issues, surpassing the total fixes from the previous 23 stable releases combined. By late July, over 1,800 security vulnerabilities had been resolved, with version 151 adding another 370 patches. Google is also piloting twice-weekly security updates to shorten the time between discovering a flaw and delivering the fix to users. Automated triage and patch generation could soon make this process even faster, shrinking it from days to mere hours.
The discovery method used by Google's AI could influence security practices beyond Chrome, shining a light on how machine learning can help uncover long-standing vulnerabilities. As AI tools become more sophisticated, their role in cybersecurity is only set to grow.
This is informational content and not financial advice.



