Find out what AI could save you — calculate your automation ROI for free in minutes
Yowox.
News · By Alex

Chrome fixed 1,072 security bugs across two June releases

Google says Chrome 149 and 150 fixed 1,072 security bugs with AI-assisted discovery and repair, exceeding the 1,036 fixed across the previous 23 milestones.

Share
Chrome fixed 1,072 security bugs across two June releases

Google says Chrome 149 and 150 fixed 1,072 security bugs, more than the 1,036 fixed across the previous 23 milestones. The official Chrome security update gives Google's account of the broader security effort, while the comparison itself is about two June releases versus two years of earlier Chrome milestones—not every Chrome bug found in one month.

Definition: Chrome milestones are numbered stable-release versions; Chrome 149 and 150 were the two versions released in June 2026.

Proof: Google reports 1,072 security bugs fixed in those two milestones, compared with 1,036 across the previous 23 milestones.

Key takeaway: AI is increasing the volume of security work Chrome can process, while human review, testing and release speed still determine when users are protected.

Business impact: For operators, the important shift is from occasional vulnerability response to an always-on pipeline that can discover, prioritize, fix and ship security work at software-development scale.

What changed in Chrome’s June releases?

Chrome’s June result is a release-milestone comparison, not a simple monthly bug count. Chrome 149 and Chrome 150 together fixed 1,072 security bugs, while the 23 earlier milestones beginning around Chrome 126 accounted for 1,036 fixes across the prior two years; that is the numerical basis for Google’s claim that recent output surpassed the earlier period.

Chrome release groupMilestones includedSecurity bugs fixed
Recent June releasesChrome 149 and 1501,072
Previous two-year comparison23 milestones1,036

The distinction matters because “bugs fixed in June” can imply that one calendar month produced 1,072 fixes. The evidence supports a narrower statement: two Chrome stable milestones released in June contained that many security fixes, and the total exceeded the prior 23-milestone comparison.

How did AI enter the Chrome security story?

TechCrunch reports that Google used internal AI tools to help identify and patch Chrome security flaws at a larger scale. The company published a chart and a white paper about using AI to find vulnerabilities and repair them faster; the takeaway is that the result reflects a security-process change, not simply a new Chrome feature exposed to users.

Google Chrome engineering director Doug Turner said LLMs have “fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation.” Google also said models such as Gemini can help fix vulnerabilities preemptively, which frames AI as a defensive response to the growing volume and speed of software flaws. The distinction between a model and the system around it resembles the governed AI agent loop, although the source does not disclose Google's internal implementation in full.

What does the result mean for vulnerability management?

AI changes the economics of vulnerability management by making more code review and repair activity possible before attackers exploit a weakness. Doug Turner, Chrome’s director of engineering, told TechCrunch that LLMs have shifted vulnerability discovery toward an automated, industrial-scale operation; the operational takeaway is that defenders need pipelines that can absorb more findings without turning triage into a new bottleneck.

The broader trend is not limited to Chrome. TechCrunch also reported that Microsoft had patched a record 570 security flaws across its product lines and cited its own use of AI, while an independent count put Apple at 482 fixes in 2026. Those figures are not directly comparable with Chrome’s milestone totals, but they support the narrower conclusion that AI-assisted vulnerability work is changing how large software vendors measure defensive output.

The comparison still needs careful reading. The 1,072 figure covers security bugs fixed in two Chrome versions, not all Chrome bugs, and it does not prove that AI alone caused every fix. The useful signal is the scale of the claimed change: Google is reporting more security fixes in two recent milestones than across the previous 23 milestones combined.

What should security teams watch next?

The next meaningful question is whether other software vendors can reproduce the same increase in security fixes without making their comparisons impossible to interpret. Chrome’s result is a milestone count, Microsoft’s figure covers product lines, and Apple’s number comes from an independent count; security teams should therefore compare definitions and release windows before treating any one total as a universal benchmark.

The broader lesson from Chrome is that AI security tooling is becoming an operational system, not a standalone vulnerability scanner. Google’s 1,072-fix result shows what happens when a vendor connects vulnerability discovery and repair at large scale. That emphasis on governed, reviewable security workflows also appears in Yowox’s analysis of agentic cybersecurity platforms. The remaining question is whether higher automated throughput consistently produces fixes that reach users before attackers can exploit the underlying flaws.

Frequently asked questions

How many Chrome security bugs did Google say it fixed in June?

Google said Chrome 149 and Chrome 150, the two milestones released in June, fixed 1,072 security bugs. The comparison is with the previous 23 Chrome milestones, which together accounted for 1,036 fixes over roughly two years. The figures describe security bugs fixed in released Chrome versions, not every functional bug in the browser and not a count of vulnerabilities found in one calendar month alone.

How is Google using AI to secure Chrome?

Google says its internal AI tools help find and patch Chrome security bugs at a much larger scale. The company specifically points to models such as Gemini for preemptive vulnerability fixes. The published comparison does not show that AI handled every fix, so the result should be read as evidence of AI-assisted security work rather than a fully autonomous replacement for Chrome's security engineers.

Does the 1,072 figure mean Chrome is fixing all of its bugs with AI?

No. The figure covers security bugs fixed in Chrome 149 and Chrome 150, not every functional bug in the browser. Google attributes the increase to help from internal AI tools, but the public comparison does not establish that every one of the 1,072 fixes was generated by AI or that AI was the only factor behind the higher total.

Is Chrome the only browser or software product seeing more AI-assisted fixes?

No. TechCrunch also reported that Microsoft attributed a record 570 security fixes across its products to its use of AI. The same report said an independent count put Apple's 2026 fixes at 482, although Apple did not confirm an AI explanation. These comparisons are not identical product sets, but they show why the change is being discussed as a broader defensive-security trend.

Alex

Alex

Founder & Lead AI Writer

Alex is the founder of Yowox and lead AI writer since 2024, breaking down complex information into clear, actionable insights for thousands of readers every day. Alex has built AI automation systems for businesses since 2024, focusing on AI agents, workflow automation, and business process optimization.

Save hours. Save thousands.

Practical guides, real workflows, and the latest AI and automation news that matters — straight to your inbox.

More from Yowox