AI Finds 1,442 Chrome Bugs in Three Recent Releases
Google patched 1,442 security flaws across Chrome 149, 150, and 151 — more than the prior 23 releases combined. AI-assisted testing drove the surge.
1,442 security bugs. Three Chrome releases. More than Google patched in the prior 23 milestones combined.
The Hacker News and BleepingComputer confirmed the figures, citing Google. Chrome 149 and 150, released in June, account for 1,072 of them — a count that already exceeded every flaw Google fixed across Chrome 126 through 148 combined. Chrome 151, released Wednesday July 30, adds 370 more. Of those 370, 349 were reported by Google’s own teams.
Driver: AI. Google expanded AI-assisted security testing across the Chrome development pipeline. The bug count followed.
By the numbers
| Release | Bugs fixed | Notes |
|---|---|---|
| Chrome 149 + 150 | 1,072 | More than prior 23 releases combined |
| Chrome 151 | 370 | 349 reported by Google |
| Total | 1,442 |
What this means
Severity breakdown of the AI-found bugs: unconfirmed in current reporting. No individual CVE IDs were cited in either source. That gap is worth watching — 1,000 low-severity informational flaws reads differently than 1,000 memory corruption issues.
[Analysis] Two readings are available. First: AI is finding a large latent inventory of bugs that existed and went undetected under prior processes. Second: AI is genuinely accelerating the discovery-to-patch cycle faster than adversarial research can keep pace. The magnitude of the jump — more than all prior 23 releases combined — suggests this isn’t noise. Which reading matters more depends on severity distribution and whether any of these bugs were independently found and exploited before Google caught them. Neither is confirmed in current reporting. Treat accordingly.
What to do
Chrome 151 is current. Default auto-update handles desktop installs.
For managed deployments: confirm fleet is on Chrome 151 or later, and verify update policies aren’t holding an older channel. Enterprise and embedded Chromium builds may require a manual push. Check your channel assignment before assuming coverage.
No CVE IDs cited in current reporting. If high-severity identifiers emerge from this disclosure batch, this page will be updated.
Found this useful? Share it.


