Google近期通过部署大规模语言模型和AI代理技术,显著提升了Chrome浏览器的漏洞发现和修复效率。在Chrome 149和150两个最新版本中,Google共修复了1072个安全漏洞,这一数字已经超过了之前23个版本的修复总和[1]。
Google开发的AI工具包括Naptime、Big Sleep和Gemini等,这些工具被用于自动发现漏洞、自动化漏洞分类和生成修复方案[1]。其中,AI驱动的自动分类流程每月为开发者节省数百小时的工作时间[1]。在2025年早期,Google使用Gemini构建的代理发现了一个存在13年以上的沙箱逃逸漏洞[1]。在5月份,AI工具在CI系统中阻止了超过20个漏洞进入生产环境,其中包括一个严重的S1+级安全问题[1]。
为了支持开源生态应对安全威胁,Google向Alpha-Omega项目捐赠了1250万美元,用于帮助开源项目维护者处理漏洞报告[1]。此外,Chrome拥有2300多个第三方依赖,其中约1700个被发送到用户端[1]。2026年3月,Chrome Vulnerability Reward Program收到的漏洞报告数超过了2025年全年的总数[1]。
Google has dramatically accelerated the pace of security vulnerability fixes in Chrome through the deployment of artificial intelligence tools. [1] In the two latest browser versions, Chrome 149 and 150, the company patched 1,072 security flaws—a figure that surpasses the combined total of fixes across the previous 23 versions. [1] This surge in remediation speed reflects Google's broader effort to harness large language models and AI agents to streamline vulnerability discovery and repair workflows.
The acceleration stems from AI-driven tools developed between 2024 and 2026, including systems named Naptime, Big Sleep, and Gemini, which automate flaw identification, vulnerability classification, and patch generation. [1] An AI agent built with Gemini identified a sandbox escape vulnerability that had persisted for over 13 years, discovered in early 2025. [1] The automated classification process now saves developers hundreds of hours monthly. [1] In May, AI-powered systems deployed within the continuous integration pipeline blocked more than 20 vulnerabilities from reaching production, including one classified as critical S1+. [1]
The initiative has prompted broader industry action. In March 2026, Google's Chrome Vulnerability Reward Program received more bug reports in a single month than throughout the entirety of 2025. [1] To support the community response to this surge in vulnerability disclosures, Google contributed $12.5 million to the Alpha-Omega project, which assists open source maintainers. [1] Chrome currently relies on over 2,300 third-party dependencies, approximately 1,700 of which are shipped to users. [1]