Summary

Google has internally discovered over 200 Chrome vulnerabilities in the past month alone, a dramatic surge that security researchers attribute to the company’s deployment of AI-powered vulnerability discovery tools. The trend is stark: Chrome advisories went from a handful of internally-found bugs in late March to 16 in mid-April, 21 by late April, and then an explosive 100 in a single May 5 advisory. Over 70 more followed in the two most recent Chrome releases.

While Google hasn’t explicitly confirmed which AI model is driving the discoveries, the company acknowledged that “the latest advancements in AI” have helped its teams move “at an unprecedented rate” and that AI makes it “significantly easier to take a test case and explain the root cause, propose a suitable fix, and find variants of known problems.” Google recently unveiled CodeMender, a DeepMind-developed AI code security agent that autonomously identifies vulnerabilities, recommends fixes, and tests patches.

The trend isn’t limited to Google. Mozilla recently found over 270 Firefox vulnerabilities using Anthropic’s Claude Mythos model, and both Microsoft and Palo Alto Networks have reported similar surges from AI-assisted code analysis on their own products.

Source

SecurityWeek · Chrome Releases Blog

Commentary

This is what the “AI finds vulnerabilities faster than humans” era actually looks like — and it’s a double-edged sword. On the defensive side, finding and patching 200+ bugs before attackers do is an unqualified win. Chrome’s attack surface shrinks meaningfully with every release. But the same AI capabilities are available to offensive researchers and threat actors. If Google’s internal tooling can find this many bugs this fast, what are well-resourced adversaries finding in software that doesn’t have a dedicated AI security team?

The broader implication is clear: the vulnerability discovery arms race has entered a new phase. Organizations that aren’t using AI to audit their own code are falling behind both attackers and defenders simultaneously. Google’s lowering of Chrome bug bounties makes strategic sense in this context — external researchers simply can’t compete with an AI that scans the entire codebase continuously. The era of manual bug hunting as a primary security strategy is ending.

By Allan