AI Boosts Chrome Security: Finds & Fixes Bugs Faster

Jul 30·0:00 listen·Source: Help Net Security

Summary

Google is significantly expanding its use of AI to enhance Chrome's security. AI now helps find vulnerabilities, triage bug reports, generate patches, and review code. This aims to quickly move from discovering flaws to delivering security updates. Historically, triaging a single security report took five to thirty minutes and relied heavily on human expertise. Google is now shifting towards a more automated approach, blending rule-based systems with AI for increased speed and accuracy. One AI-powered system, based on Gemini, found a sandbox escape vulnerability that had been in the Chrome codebase for over 13 years. This flaw could have allowed a compromised process to access local files. AI also assists with remediation, generating candidate patches and reviewing proposed fixes. Google reported that Chrome 149 and 150 included fixes for 1,072 security bugs, surpassing the total from the previous 23 stable releases combined. This higher number indicates improved detection, not a decline in security. Google is also working to reduce the "patch gap," the time between a security fix being published and users installing the update. They are piloting two security releases a week and developing dynamic patching to update key components without a full restart. This matters because a shorter patch gap means users are protected faster from potential threats.

Read the full article on Help Net Security

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening