Chrome is now patching security holes twice a week, and AI found most of them
Google's browser shipped more security fixes in two releases last month than in the previous 23 combined. AI tools scanning its own code are the reason, and the pace may get faster before it slows down.

Key points
- Google's Chrome browser shipped fixes for 1,072 security bugs across its two major releases in June 2025, more than the previous 23 major releases put together.
- Chrome's security team is now piloting patches twice a week, up from the previous rhythm of one major update every two weeks with additional weekly security updates.
- The spike is driven largely by AI tools that Chrome's own engineers use to find vulnerabilities, triage them and write fixes.
- Google trains its AI models on every past Chrome security flaw and every line of code in the browser's history, helping it spot patterns humans would miss.
- Chrome's VP Parisa Tabriz told Wired that 2025 feels like "an inflection point both for offense and defense."
Google shipped fixes for 1,072 security bugs in Chrome's two June 2025 releases, more patches than the team pushed out across the previous 23 major releases combined. AI, applied from the inside, explains almost all of it.
What is Chrome's team actually doing?
Chrome's engineers are using AI tools to find weaknesses in the browser's own code, prioritise which ones matter most and help write the fixes. Chrome's VP and general manager Parisa Tabriz told Wired the team has used machine-learning tools for security testing since at least 2012, but called 2025 "very different" and "an inflection point."
What the team feeds its models matters. Doug Turner, Chrome's director of engineering, says the AI knows every CVE (an officially numbered record of a known security flaw) Chrome has ever had, plus the full history of why every line of code was ever changed. That context lets it home in on corners of the codebase that human reviewers rarely visit, including features like printing that are no longer under active development.
Two weeks before this story, our report on Google's Gemini 3.5 Flash Cyber model showed a related AI finding 55 bugs in Chrome's engine that competing tools had missed, at a fraction of the cost. The throughput numbers now arriving from the Chrome team suggest that was a preview of a much larger shift.
Should Chrome users be worried about all these bugs?
Not especially. Finding and fixing bugs fast is the good outcome. The concern would be bugs found by attackers first, not by Google's own tools.
Turner sees early signs the current frenzy won't last. Once AI sweeps through a mature codebase and the bulk of hidden flaws are patched, the discovery rate should fall: there's a ceiling to how many vulnerabilities any given piece of software contains.
Beyond patching individual flaws, the Chrome team is rewriting portions of the browser in Rust, a programming language that eliminates whole categories of memory-related bugs that have plagued software for decades. That's the structural fix, not just the whack-a-mole work.
"There's this near-term spike, but I do think there's going to be a new equilibrium," Tabriz said.
What does this mean for the rest of the software industry?
Chrome is one data point, but the same AI scanning tools are available to anyone building software and to attackers hunting for flaws to exploit. Tabriz was direct: getting more secure won't come for free, and teams not using AI in their security workflows are already behind.
Your Chrome browser updates itself automatically, so no action is needed on most devices. If you've ever turned off automatic updates, re-enable them now. Go to Chrome's settings, select "About Chrome" and let it check for the latest version.



