Google's Gemini AI Patches More Chrome Bugs Than Two Prior Years
Google shipped 1,072 Chrome security fixes in June alone, powered by its Gemini models. The numbers hint at a new arms race that Indian banks and CERT-In cannot ignore.
The News
Google has patched 1,072 security bugs in Chrome versions 149 and 150, both released in June 2026, a haul that comfortably beats the 1,036 fixes the company shipped across the previous 23 releases over two full years. In other words, a single month now matches what used to take Google roughly 24 months to clear.
The company credits its Gemini models for the surge. "By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update," said Doug Turner, Chrome's director of engineering. The idea is that large language models can read source code, spot flawed patterns and surface vulnerabilities faster than human reviewers working alone.
Google is not alone. Microsoft patched 570 security flaws in its mid-July "Patch Tuesday" cycle, also pointing to AI as the accelerant. Apple, by contrast, has fixed 482 bugs across 2026 with no comparable spike, suggesting the shift is a strategic choice rather than an industry-wide inevitability.
Why It Matters
For two years, security researchers have argued that machine-driven code analysis would eventually outpace manual review. These figures are among the first hard numbers to back that claim at production scale inside the world's most-used browser.
The last time bug-hunting saw a step change of this kind was 2016, when Google open-sourced OSS-Fuzz and DARPA staged its Cyber Grand Challenge, proving that automated systems could find and fix flaws without a human in the loop. Those tools brute-forced their way to results. Gemini reasons over code instead, which is why the curve is now bending sharply upward rather than climbing in a straight line.
There is a catch worth naming. Finding more bugs does not automatically mean software is safer. A rising fix count can also signal how many latent flaws were sitting undiscovered, and attackers are pointing the same models at the same code. The advantage goes to whoever patches first, which is precisely the race Turner described.
Indian Angle
Chrome is the default gateway to the internet for the overwhelming majority of India's online population, from UPI payments to net-banking dashboards. A browser that quietly closes vulnerabilities faster directly lowers the attack surface for millions of Indian users who never install a separate security tool.
For regulated institutions, the timing matters. CERT-In's 2022 directions already require covered entities to report incidents within six hours and to keep tight logs, while the RBI's cyber-security framework holds banks accountable for the software their customers touch. If browser vendors can pre-empt flaws at this pace, Indian banks and fintechs gain breathing room, but regulators will also expect them to roll out patched versions just as quickly. Slow enterprise update cycles, common across public-sector banks, become the weak link.
There is an opportunity too. India's security talent pool, which staffs a large share of global SOCs and bug-bounty leaderboards, is well placed to build the review and triage layers that AI-found vulnerabilities still demand. Homegrown firms working on AI-assisted code auditing, and startups eyeing the DPDP-era compliance market, now have a clear proof point that the approach works at scale.
FAQ
What exactly did Google announce?
Google said it fixed 1,072 security bugs in Chrome 149 and 150, released in June 2026, exceeding the 1,036 fixes shipped across the prior 23 versions over two years. It attributed the jump to its Gemini AI models being applied to vulnerability discovery.
Does more bug fixes mean Chrome is now safer?
Not automatically. A higher count shows more flaws are being found and closed, but it also reveals how many were previously undiscovered. Since attackers can use similar AI tools, the real edge lies in patching faster than adversaries can exploit.
How does this affect Indian users and banks?
Most Indian users reach banking and UPI services through Chrome, so faster fixes reduce their exposure directly. Banks and fintechs under CERT-In and RBI rules must still deploy updated versions promptly to capture the benefit.
Where can I read the original report?
TechCrunch published the original coverage, including Doug Turner's remarks and the Microsoft and Apple comparisons. The link appears in the attribution below.
This story was reported by TechCrunch. Read the full original coverage at TechCrunch.