Google pilots twice-weekly Chrome patches as AI finds record bugs
Gemini-powered discovery led Google to patch more vulnerabilities in June 2026 than in the previous 23 major releases combined.
Google is fundamentally altering the release cycle of its Chrome browser, piloting a security update cadence that rolls out patches up to twice per week. The shift comes as internal AI tools trigger a massive surge in vulnerability discovery, forcing the company to accelerate its deployment pipeline to keep pace with the volume of fixes.
In June 2026, Google patched 1,072 security bugs across Chrome versions 149 and 150. This single-month effort surpassed the 1,036 total fixes delivered in the previous 23 major releases combined. The company attributes this unprecedented spike to the integration of Large Language Models (LLMs), specifically Gemini, to automate the discovery, triage, and remediation of vulnerabilities.
The AI Arms Race
This acceleration realizes a long-predicted "arms race" in cybersecurity. Experts have warned for years that LLMs would exponentially increase the volume of discoverable software flaws, requiring defenders to adopt the same AI tools to counter AI-powered attackers. While some competitors have seen stable patching volumes, other tech giants are reporting similar spikes as they integrate AI assistance into their security workflows.
A Shift in Cybersecurity Economics
According to Doug Turner, Chrome’s director of engineering, LLMs have "fundamentally shifted the economics of cybersecurity," turning the search for vulnerabilities into an "automated, industrial-scale operation." By utilizing Gemini, Google aims to preemptively fix flaws before they can be weaponized. Turner noted that this approach allows the team to outpace adversaries and increase the browser's overall security with every update.
The New Update Standard
This transition marks a move away from traditional monthly or bi-weekly update cycles. Because AI can now identify flaws at a speed that far exceeds human capacity, the window between discovery and exploitation has shrunk. The move to twice-weekly patching is a necessary structural response to prevent attackers from utilizing AI-found flaws before a vendor can deploy a fix.
What to Watch
As Google continues to pilot this dynamic patching model, the industry will be watching to see if this becomes the new standard for all major software ecosystems. While the record pace of patching in June demonstrates the power of AI-driven defense, it also highlights the inherent fragility of complex codebases. It remains to be seen if this industrial-scale discovery will eventually exhaust the pool of low-hanging fruit or if AI will continue to uncover deeper, more systemic architectural flaws.