Chrome Requires Biweekly Updates Due to AI-Driven Bug Detection

Chrome Requires Biweekly Updates Due to AI-Driven Bug Detection

Google’s Chrome browser has consistently prioritized security updates. Ten years ago, it was a point of contention that the browser, the first to implement automatic updates, rolled out patches every six weeks. Today, it’s commonplace for essential software to receive security updates every few weeks. However, as AI-driven vulnerability detection uncovers a flood of bugs across various software, the volume and frequency of these patches are surging—and the race to release them is intensifying.

In a report released Thursday, the Chrome security team revealed that the browser’s two major version updates in June addressed 1,072 security vulnerabilities—more than the total from the previous 23 significant releases combined. Although many of these vulnerabilities were identified through researcher submissions, this increase has been primarily fueled by the Chrome security team’s rapidly advancing internal processes that leverage AI tools for vulnerability detection, triage, and patch creation.

“For Chrome, we’ve been utilizing machine learning—essentially using AI before it was termed AI—to discover vulnerabilities and automate security fuzz testing since at least 2012. This has played a crucial role in our vulnerability detection and in empowering developers,” says Parisa Tabriz, Chrome’s vice president and general manager, in an interview with WIRED. “However, I believe this year marks a significant shift. It genuinely feels like a turning point for both offense and defense.”

Chrome is already progressing toward a new standard of major releases every two weeks, supplemented by weekly security updates. Yet, the sheer volume of vulnerability discoveries has been unprecedented, and the success of integrating new AI models and technologies into the bug discovery and resolution process has led the team to experiment with a schedule of releasing security updates twice a week.

“We reached this point due to the sheer number of vulnerability fixes. Providing two updates per week during this period felt logical,” remarks Doug Turner, Chrome’s director of engineering. “Will this approach continue indefinitely? Only time will tell.”

Turner, along with other security researchers, suggests that the current surge in AI-driven vulnerability discovery (which some may consider an apocalypse, depending on perspective) might not persist indefinitely. For established, stable products like Chrome, there appears to be a saturation point where the discovery of new vulnerabilities starts to diminish once most bugs that can be detected through AI have been resolved. This is in part because AI models can be trained to have a comprehensive understanding of the evolution of software projects over time.

“We are training our model to be aware of every security vulnerability we’ve encountered in the past,” Turner explains. “Thus, it knows every CVE, every bug. Additionally, it understands the rationale behind every line of code adjusted in Chromium’s history.”

This contextual knowledge equips AI tools to pinpoint potential vulnerabilities within Chrome’s extensive and complex codebase, including features (such as printing) that may no longer be actively developed and thus receive less scrutiny from human reviewers.

Tabriz and Turner further highlight that, in addition to reactive patching, the Chrome security team is also deeply committed to implementing structural modifications to the browser’s design, such as rewriting certain C++ code segments in a more secure, “memory-safe” programming language like Rust. This approach aims to eliminate entire categories of prevalent bugs.

“There’s a noticeable short-term surge, but I believe we will eventually find a new equilibrium,” Tabriz states. “It’s crucial that developers and those prioritizing software security across the industry integrate AI into their development workflows. My greatest hope is that security improves universally. However, I don’t take for granted that this will happen effortlessly. I don’t believe it will come without effort.”

https://in.linkedin.com/in/rajat-media

Helping D2C Brands Scale with AI-Powered Marketing & Automation 🚀 | $15M+ in Client Revenue | Meta Ads Expert | D2C Performance Marketing Consultant