Google宣布计划对Chrome浏览器的更新机制进行调整[1]。由于AI安全模型能够快速识别软件漏洞,Chrome最近两个主要版本(149和150)共修复了1,072个漏洞,这一数字已经超过此前23个版本修复漏洞总数[1]。为了应对日益增加的AI驱动攻击威胁,Google正计划显著缩短更新周期,从当前的两周一次调整为每周两次[1]。
同时,Google还在探索实现无需重启即可推送更新的技术方案[1]。安全研究人员发现了一个隐藏在Chrome代码库中13年的漏洞,该漏洞若被利用可能绕过Chrome沙箱并访问本地文件[1]。
Google is preparing to overhaul Chrome's update mechanism in response to accelerating security threats. The company has detected an alarming surge in vulnerabilities, with the two most recent major versions—149 and 150—addressing 1,072 bugs combined, exceeding the total number of flaws fixed across the preceding 23 versions [1]. This dramatic shift reflects the growing impact of AI-driven vulnerability detection on the browser's security landscape.
To mitigate emerging threats, Google is moving toward more frequent release cycles, currently testing a system that would push updates twice weekly rather than the present biweekly schedule [1]. The effort extends beyond accelerating patch deployment; the company is also investigating methods to deliver updates without requiring users to restart the browser [1]. Among the vulnerabilities highlighted is a critical flaw that lay dormant in Chrome's codebase for 13 years and, if exploited, would allow attackers to circumvent Chrome's sandbox protections and access local files [1].