Google patched 1,072 security bugs across the last two versions of Chrome, Chrome 149 and Chrome 150, both released in June 2026. That single month of fixes exceeds the 1,036 patches shipped across the previous 23 Chrome versions combined over the prior two years. The company credits its internal use of large language models, chiefly Gemini, for the step change.
The scale of the jump is not incremental. Chrome 126, released in June 2024, sat at the low end of a curve that had been climbing slowly for years. The two June 2026 releases sit on a near-vertical line above it. Google published the underlying chart alongside a white paper detailing how it now applies AI to vulnerability discovery and patching across the browser's codebase.
Doug Turner, Chrome's director of engineering, framed the shift in economic terms rather than technical ones. The cost of finding a bug has collapsed, and the party that industrializes that discovery first gets to fix flaws before attackers weaponize them.
Key facts
- 01Google patched 1,072 security bugs across Chrome 149 and 150, both released in June 2026.
- 02That single month exceeded the 1,036 fixes shipped across the previous 23 Chrome versions over two years.
- 03Chrome director of engineering Doug Turner credited Gemini and other LLMs for the automated bug discovery.
- 04Microsoft patched a record 570 flaws in its July Patch Tuesday, also citing AI-assisted discovery.
- 05Apple patched 482 bugs in 2026, roughly flat with its 2015 pace and showing no comparable AI-driven jump.
The prediction that AI would break the offense-defense balance in cybersecurity is not new. Security researchers have warned for at least two years that LLMs would let both attackers and defenders find bugs at a pace that human review teams could not match, forcing every large vendor to either automate their own discovery pipeline or fall behind. Google's numbers are the first public data point suggesting the transition has actually happened at a top-tier vendor.
Microsoft is seeing the same curve. Earlier this month, the company patched a record 570 security flaws across its product lines in a single Patch Tuesday, and explicitly cited its own AI tooling as the reason for the sudden jump. Two of the three largest software vendors in the world are now shipping monthly patch volumes that would have been considered a full-year output as recently as 2024.
Apple is the outlier. An independent count puts Apple at 482 bugs patched in 2026, a pace that is roughly in line with 2025 and, remarkably, roughly in line with the 2015 total. Apple has not publicly detailed any comparable AI-driven discovery program, and did not respond to a request for comment. Whether that reflects a different security posture, a smaller attack surface being counted, or simply a slower adoption of internal AI tooling is not clear from the outside.
“By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update.”— Doug Turner, Chrome director of engineering
The optimistic read on Google's number is that a large stockpile of latent vulnerabilities is being drained faster than attackers can find and exploit them. Chrome ships to billions of users, and every bug fixed preemptively is one that never becomes a zero-day. The more cautious read is that raw patch counts are not a security metric on their own — a browser that fixes 1,072 bugs in a month may simply have had 1,072 bugs waiting to be found, and the same LLMs helping Google are available to anyone with an API key.
That symmetry is the open question. Google, Microsoft and other defenders have privileged access to their own source code, which gives their AI tooling a structural advantage over external attackers working from binaries. But attackers do not need to find every bug — they need to find one. If LLM-driven fuzzing and code review scale as well for offense as for defense, the pace of patching becomes a treadmill rather than a lead.
For Google, the immediate payoff is competitive. Chrome's security reputation is one of the reasons enterprises standardize on it, and being able to point to a chart showing an exponential increase in fixes shipped is a marketing asset as much as a technical one. It also reinforces Gemini's positioning inside Google's own product stack — the model is not just a consumer chatbot but a working piece of the company's internal security infrastructure.
The broader signal is that AI has moved from a research curiosity in security to a line-item capability that shapes patch cadence at the largest vendors. Companies that do not build or license comparable tooling will find their monthly patch counts looking increasingly small next to Google's and Microsoft's, and customers will notice. The next twelve months will show whether Apple's flat curve is a deliberate choice, a lagging investment, or a different definition of what counts as a bug worth fixing.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




