Chrome Bug Discovery Is Outrunning Release Cadence
The shift is not that Chrome has one especially bad flaw. It is that AI-assisted discovery is now surfacing bugs faster than Google can package, publish, and ship fixes, so the exposure window grows for any unpatched user even when disclosure is public.
Google says Chrome 149 and 150 fixed 1,072 security bugs, and Chrome 151 added 370 more, for 1,442 across three releases. It also says 349 of the 151 fixes came from Google itself, and one AI-found sandbox escape in Navigation had sat in the code for more than 13 years.
The practical change is in cadence. Google is piloting two security releases per week and more automation around release notes because the backlog is moving faster than normal patch throughput can absorb it.
CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.4% (29th percentile). Microsoft patch: Release Notes.
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 41 nuove vulnerabilità di sicurezza, di cui 6 con gravità “critica” e 35 con gravità “alta”.