
Google announced Thursday that it fixed 1,072 Chrome security bugs in June—more than the 1,036 bugs patched over the previous two years—by deploying internal AI tools to automate vulnerability discovery.
The shift underscores a broader industry turn toward AI-powered cybersecurity, as defenders race to match the speed of attackers also using AI.
However, the trend is not universal: Apple's 2026 bug-fix pace remains steady rather than exponential.
What happened
Google announced Thursday that it patched 1,072 security bugs across Chrome 149 and 150, both released in June, exceeding the 1,036 bugs fixed across the previous 23 versions released over the past two years combined. The company credits its use of internal AI tools, particularly models like Gemini, for the acceleration.
Why it matters
Doug Turner, Chrome's director of engineering, stated that LLMs have "fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation." This represents a shift in how tech companies defend against threats—defenders now use AI to keep pace with AI-powered attackers. Microsoft similarly reported a record 570 security patches in its monthly cycle this month, citing AI as the driver.
What to watch
The trend is not uniform across the industry. Apple, by contrast, has patched 482 bugs in 2026, roughly on pace with 2015 levels and last year's total—no sign of the exponential jump seen at Google and Microsoft. The disparity suggests different AI adoption strategies among major vendors.
On Thursday, Google disclosed a striking acceleration in its Chrome security patch rate, powered by internal AI tools. The company fixed 1,072 security bugs across two Chrome releases—versions 149 and 150—both deployed in June. To put this in perspective, that single month's output exceeded the total of 1,036 bugs patched across the previous 23 Chrome versions released over the prior two years.
Google revealed this data as part of a white paper detailing its efforts to use AI to find and patch vulnerabilities faster. The company's AI models, particularly Gemini, have been deployed to automate the vulnerability discovery process. Doug Turner, Chrome's director of engineering, explained the shift in a statement to TechCrunch: "LLMs have fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation. By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update." Chrome version 126, released in June 2024, serves as the baseline for comparison; the latest releases, Chrome 149 and 150, came out last month.
Google is not alone in experiencing this trend. Earlier this month, Microsoft announced a record 570 security patches across its product lines as part of its monthly Patch Tuesday cycle, citing AI as the cause of the jump. Apple, however, presents a different picture. An independent count shows Apple has patched 482 bugs in 2026, a pace roughly equal to last year's total and similar to the count from 2015—no exponential increase. TechCrunch reached out to Apple for comment but received no response, leaving open the question of whether Apple's steadier patch rate reflects a deliberate strategy or a slower rollout of AI-powered security tools.
Google's announcement reflects a fundamental shift in the cybersecurity landscape, one predicted by experts since the rise of large language models. For years, security researchers warned that AI systems would dramatically accelerate vulnerability discovery, forcing defenders to adopt the same technology or fall behind. Google's data now confirms this prediction: the jump from 1,036 bugs over 23 months to 1,072 in a single month demonstrates the scale of the change.
The comparison across vendors is instructive. Microsoft's separate announcement of a record 570 patches in a single monthly cycle corroborates Google's finding and suggests the trend is real and industry-wide. Yet Apple's steady pace—482 fixes in 2026, comparable to 2015 and 2024 levels—indicates that adoption of AI-powered bug detection is not universal. This divergence may reflect different engineering priorities, different existing vulnerability backlogs, or different timelines for integrating AI into security workflows. Doug Turner's statement that AI has transformed "vulnerability discovery into an automated, industrial-scale operation" captures the shift: what was once a labor-intensive process is becoming automated, forcing all major players to decide whether and how quickly to adopt similar tools.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
ByteDance is reorganizing Doubao (its AI chatbot), Lark (workplace software), and Volcengine (cloud infrastruc…

Nvidia CEO Jensen Huang identified memory chips as AI's largest bottleneck, shifting focus from the earlier pr…

OpenAI cut GPT-5.6 Luna prices by 80% (now $0.20 per million input tokens and $1.20 per million output tokens)…

Anthropic disclosed that three Claude models—Opus 4.7, Mythos 5, and an internal research test model—gained un…

Hitachi announced the Agentic AI Integration Platform, which applies AI agents across the entire systems integ…

Amazon is positioning itself as the platform provider for AI rather than competing to build the best AI model

The AI news that matters, in one minute each morning.
Sign up free