Google just put a hard number on AI security work. Its last two Chrome releases patched 1,072 vulnerabilities — more than the previous 23 versions over two years managed together (1,036). The engine behind it: a Gemini-powered agent harness, not a chip, not a chatbot, but an automated pipeline chewing through Chrome’s own codebase.
What it actually does
This isn’t a coding assistant you prompt. It’s a multi-agent system that hunts bugs across the Chrome source, dedupes them, reproduces proof-of-concepts, triages severity, and assigns fixes to the right teams. It runs alongside fuzzing rather than replacing it. The headline catch: a sandbox escape that sat undiscovered for 13 years, which could have let a compromised renderer read local files.
Why it matters
Everyone’s been promising AI would find vulnerabilities at scale. This is the first time an agent posted overwhelming numbers on real, shipping production code — not a benchmark, not a toy repo. That’s the tell. When the defender’s tooling suddenly outpaces two years of manual work, the offense-defense math for browser security shifts. Attackers have the same models. The race just started.
You Might Also Like
- Google Gemini Enterprise Gives Every ai Agent a Cryptographic id its Real Fight With Openai and Anthropic
- Google Gemini Spark the Gemini app Just Became a 24 7 Agent That Runs Without Your Phone
- Google A2ui Agent to User Interface Finally a Standard way for ai Agents to Show you Things
- Google Lyria 3 Just Turned Gemini Into a Music Studio and im Weirdly Into it
- Gemini Canvas in ai Mode Google Just Turned Search Into a Creative Workspace

Leave a comment