Google said on July 30, 2026 that its two June releases of Chrome — 149 and 150 — patched 1,072 security bugs, more than the 23 previous versions over the past two years combined (1,036). The company attributes the jump to internal AI tools, including Gemini models, that automatically find and patch vulnerabilities.
Key takeaways
- 1,072 security bugs patched in Chrome 149 and 150 (June 2026).
- That exceeds the 1,036 fixes across the previous 23 versions over two years combined.
- Google uses internal AI tools, including Gemini models, to detect vulnerabilities.
- Microsoft reported 570 security patches in July 2026 using AI.
- Apple showed no comparable exponential increase.
What Google announced
The numbers land in the comparison. In two June 2026 releases — Chrome 149 and 150 — 1,072 security bugs were patched. By comparison, over the prior two years, from Chrome 126 to 148 across 23 versions, there were 1,036 fixes. In other words, one month beat two years. Google also published a white paper describing its AI-assisted vulnerability-detection methods.
How it works
According to Doug Turner, Chrome's director of engineering, AI has shifted the economics of cybersecurity, turning vulnerability discovery into an automated, industrial-scale operation. Instead of waiting for an attacker or outside researcher to find a flaw, the models comb through the code and flag bugs before they ship. That moves the center of gravity from reaction to prevention.
By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update.
Doug Turner, Chrome's director of engineering, Google.
How the industry compares
Google is not alone. Microsoft reported 570 security patches in July 2026, also using AI. Apple, according to the analysis, showed no comparable exponential increase. The divergence between the companies suggests that patching pace increasingly depends on how aggressively a company wires AI models into its code-review process.
| Company | Patches | Period |
|---|---|---|
| 1,072 | Chrome 149–150, June 2026 | |
| Microsoft | 570 | July 2026 |
| Apple | no comparable increase | — |
Why it matters
A step-change in patch counts is a double-edged sword. On one hand, automated vulnerability discovery genuinely shrinks the window in which a flaw stays open to attack — and the browser is one of the most heavily targeted pieces of software. On the other, 1,072 fixes in a month also reveal how many bugs previously went undetected. The same mechanism that helps defenders is available to attackers: if AI can find flaws at scale in someone else's code, the race speeds up on both sides. The key question is no longer whether bugs can be found, but who finds them first. The divergence between Google, Microsoft and Apple shows that a security edge is starting to depend on the scale of AI deployment, not just headcount.
What's next?
- Google published a white paper on its AI-assisted vulnerability-detection methods.
- The gap in patching pace between Google, Microsoft and Apple will show up in coming releases.





