Google recently announced the resolution of an astonishing 1,072 security vulnerabilities in Chrome versions 149 and 150, a number surpassing all fixes made in the previous 23 updates combined. This surge in reported flaws underscores the increasingly perilous nature of browser security.
Both versions of Chrome were launched last month. The latest update, Chrome 151, released on Wednesday, addressed 370 vulnerabilities, of which 349 were identified by Google’s own security teams. Among these, seven vulnerabilities have been classified as critical, posing significant risks to users.
This uptick in vulnerabilities arises amidst a remarkable increase in the discovery of such flaws, largely driven by advancements in large language models (LLMs). These technologies have expedited the identification of bugs, leading to a situation where new issues are flagged more rapidly than companies can address them. As of 2026, the U.S. National Vulnerabilities Database has recorded 46,872 flaws, nearing the annual total of 49,920 vulnerabilities from 2025.
One notable issue identified in the Chrome codebase was a critical sandbox escape that could have allowed unauthorized access to user files. Google reported that this severe flaw had been hidden in its source code for over 13 years before being discovered through its Gemini models and subsequently patched in March.
To enhance its response to these growing threats, Google is moving towards a bi-weekly release cycle for major updates and is testing a new strategy involving two security releases per week to combat rapid, AI-powered attacks. The company emphasised that all security vulnerabilities are documented and publicly disclosed to foster transparency.
Additionally, Google is working to automate the generation of release notes and vulnerability descriptions to expedite patch deployment. It aims to introduce dynamic patching, allowing updates to be applied without requiring a complete browser restart. This innovation would improve user experience while strengthening security.
Furthermore, the company is committed to removing entire categories of security vulnerabilities by enhancing the runtime environment and transitioning to safer programming languages. By automating updates for third-party dependencies, Google seeks to ensure that all components of Chrome remain secure. Overall, these strategies are designed to protect users more effectively against potential threats.
Test Your Understanding
How much do you know?





