Google AI Uncovers 13-Year-Old Critical Chrome Bug Missed by Human Reviewers
Google's AI-powered security agent, Big Sleep, discovered a critical Chrome sandbox escape vulnerability (CVE-2026-3545, CVSS 9.8) that had existed in the codebase for over 13 years. The flaw allowed a compromised renderer to access local files on disk and had survived multiple code reviews, fuzzing cycles, and external researcher scrutiny. Google quietly patched the bug in Chrome 145 in May before publicly disclosing it. The discovery came as part of a broader AI-driven security push that fixed a combined 1,072 bugs across Chrome versions 149 and 150 — more than the previous 23 major releases combined. Google's pipeline pairs a Gemini-based fixing agent with an adversarial critic agent that actively challenges proposed patches, a process the company credits as key to the program's effectiveness.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in