
Chrome fixed 1,072 security bugs in two releases using a Gemini agent harness
Google's Gemini-based agent harness pushed Chrome 149 and 150 to 1,072 security fixes — more than the prior 23 milestones combined — and surfaced a sandbox escape that had sat in the codebase for over 13 years, letting a compromised renderer read local files. Google is piloting two security releases per week, so teams that pin or stage Chrome builds face a patch cadence running twice as fast.
Source: blog.google ↗
In early 2026, we built an agent harness that used Gemini to find vulnerabilities across the broader Chrome codebase with higher efficiency and lower false positives.
Google Chrome Security team
Why this matters
- → 1,072 security fixes in two releases — a 23-milestone total — compressed patch cycles to urgent pace.
- → AI-discovered 13-year sandbox escape shows detection scale now exceeds human capability.
- → Weekly security releases force teams to patch twice as fast; infrastructure planning required.
AI finds what humans missed