Overview
- Google has deployed custom Gemini-powered agent harnesses together with specialized tools from DeepMind and Project Zero to drive a new AI-first security pipeline for Chrome.
- The new system produced 1,072 security fixes across the recent Chrome 149 and 150 milestones and flagged a high-severity sandbox-escape bug that had been in the codebase for more than 13 years.
- Multi-agent workflows automatically triage incoming issues, generate candidate code patches, critique changes, and produce cross-platform tests to speed review and reduce manual backlog.
- Chrome is piloting a cadence of two security releases per week and a ‘dynamic patching’ feature that can apply critical fixes in the background without requiring a full browser restart.
- The shift builds on years of internal fuzzing and external bug reports and could shorten attacker exposure windows, reshape developer workflows, and increase how often users receive small, automatic security updates.