Urgent.News

What's breaking now, across thousands of outlets.

AI

Google’s Gemini AI fixes 1,072 Chrome bugs in 60 days – How it happened

TL;DR: Google’s Gemini AI agents identified and helped remediate 1,072 Chrome security flaws in 60 days, dramatically shrinking the window for attackers. The race to protect 3.5 billion Chrome users has taken a high‑tech shortcut. Instead of relying solely on human researchers, Google deployed its Gemini‑powered AI agents to hunt for bugs, triage findings, and even suggest patches. The result?…

Abstract editorial illustration

Google's latest AI system, Gemini, has significantly accelerated the process of identifying and fixing security vulnerabilities in Google Chrome. Over a span of 60 days, the AI agents managed to uncover and remediate 1,072 bugs, a feat that would have typically taken years using traditional methods. This rapid response represents a major leap forward in protecting the privacy and security of the 3.5 billion users who rely on Chrome.

The integration of Gemini into Google's vulnerability‑scanning pipeline has streamlined three key processes: automated code analysis, prioritization and risk scoring, and even patch drafting assistance. By ingesting Chrome's extensive codebase, Gemini's models were able to flag risky patterns, unsafe API calls, and legacy modules that often hide security flaws. The AI then assigned a severity score to each finding, enabling engineers to focus on those issues with the highest potential impact first.

A significant portion of the 1,072 vulnerabilities discovered were classified as high‑severity, with the ability to execute remote code or steal sensitive data. The AI's intervention led to a dramatic reduction in the window of exposure, cutting the average time from weeks to hours. This swift response not only mitigated potential threats but also freed up senior security engineers to dedicate more time to complex, creative threat modeling.

The impact of Gemini's automated bug hunting is evident in the reduced exposure window and the broad coverage of legacy code paths that were previously overlooked. Additionally, by automating the low‑level analysis, Google has been able to better allocate resources towards more intricate security tasks.

The adoption of AI agents like Gemini marks a shift in how large software platforms approach security. Rather than being auxiliary tools, AI is now being treated as integral contributors to secure code development. This trend is likely to be replicated by other browsers and operating‑system vendors, with a focus on embedding LLMs directly into build and test suites and enabling continuous, automated patch generation.

However, while AI agents like Gemini have proven invaluable in speeding up the bug-fixing process, Google emphasizes that human oversight remains crucial. Human expertise is necessary to validate findings, avoid false positives, and ensure that AI-generated patches do not introduce new issues. As AI continues to evolve, it's clear that a balanced approach combining AI's efficiency with human judgment will be essential for the future of software security.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

That changed last week.

  • AI agents caused unprecedented havoc in cybersecurity last week.
  • Hugging Face experienced first instance of attack by agentic system.
  • Anthropic reported three instances of unauthorized Claude model access.

More from Monday 3 August →