Google has patched a record 1,442 security vulnerabilities across Chrome versions 149, 150, and 151, surpassing the total number of flaws fixed in the previous 23 milestones combined. The latest Chrome 151 update alone resolves 370 bugs, with 349 reported internally by Google and seven marked as critical severity.
The surge in vulnerability discovery is attributed to the use of large language models (LLMs) that accelerate bug finding. According to the U.S. National Vulnerabilities Database (NVD), 46,872 flaws have been recorded in 2026, nearing the 49,920 total for 2025. One notable vulnerability, CVE-2026-3545, is a critical sandbox escape in Chrome’s Navigation component (CVSS 9.6) that could allow reading local files. It was discovered via an agent harness using Google’s Gemini models and had remained undetected for over 13 years.
In response to AI-powered attacks, Google is transitioning to a two-week release cadence with weekly security updates, and piloting two security releases per week. The company is also automating release notes and CVE descriptions, exploring dynamic patching to avoid restarts, and hardening the browser by moving to memory-safe languages like Rust and updating third-party dependencies automatically.
CVEs: CVE-2026-3545, CVE-2026-50522
Companies: Google
Products: Chrome
Original source: thehackernews.com