The browser security race is speeding up, and Chrome’s update calendar may be next to change.
Google is testing a new schedule that would deliver Chrome security updates twice a week as the company responds to a surge in vulnerabilities discovered through AI-powered security tools.
The move comes after Chrome 149 and Chrome 150 fixed 1,072 security bugs combined, a figure that surpassed the number of security issues patched across the previous 23 Chrome milestones, according to Google.
Google said its security teams have been using large language models to improve vulnerability discovery, bug triage and patch development. The company’s goal is to shorten the time between finding a flaw and protecting users from potential attacks.
“In the face of fast-moving, AI-powered attacks, our delivery cadence must accelerate even further. To meet this moment, we are piloting a shift to two security releases per week,” Google said in its security update report.
Google’s increased release pace is tied to improvements in AI-based vulnerability research. The company said its internal tools can now analyze Chrome’s massive codebase, identify weaknesses and help developers create fixes more quickly.
One vulnerability discovered through this process had remained hidden in Chrome’s code for more than 13 years. The sandbox escape flaw could have allowed a compromised browser process to access local files on a user’s machine.
Google said AI tools are not replacing traditional security methods but adding another layer alongside techniques such as fuzzing and external vulnerability research programs. The company is also seeing more security reports from researchers. Google said it received more external bug reports in March 2026 than it received throughout all of 2025, increasing pressure to process and fix vulnerabilities faster.
Google wants Chrome updates to become less annoying
The biggest challenge with faster security releases is not only creating patches but getting them installed.
Chrome already downloads and prepares updates in the background, but users typically need to restart the browser before security fixes take effect. Google said this delay creates a “patch gap” where attackers may have time to study vulnerabilities after fixes become public.
To address this, Google is exploring dynamic patching, a system designed to replace updated browser components without requiring a full restart.
The company has also introduced a “zero window auto-restart” feature in Chrome 150 on macOS. It allows Chrome to automatically restart and apply updates when the browser has no open windows but is still running in the background. Google has not announced when dynamic patching will become available to all Chrome users.
More Google coverage
- New Google Search AI Mode is ‘Total Reimagining,’ Says CEO Sundar Pichai
- In Major Ruling, Judge Finds Google ‘Willfully Acquired and Maintained Monopoly Power’ Over Digital Ad Market
- Google’s Big Bet on Nuclear Energy: ‘The Race to Power AI-Driven Data Centers is Accelerating’
- Computer History Museum Releases Original AlexNet Code: Why It Matters
What faster Chrome releases mean for businesses
The change will likely happen quietly for consumers. Chrome already updates automatically for most users, and Google is working to reduce the need for manual restarts.
Businesses, however, may face new challenges. Organizations that manage large Chrome deployments will need to balance faster security protection with the need to test browser updates before widespread rollout.
A twice-weekly security cycle could require IT teams to rethink update policies, especially in industries where browser compatibility is critical for daily operations. Google recommends enterprise customers use Chrome management tools, update policies, and monitoring systems to keep devices protected.
The bigger security shift
Google’s move shows how AI is changing the balance of software security. In the past, discovering vulnerabilities was often the biggest hurdle. Now, companies increasingly need to deliver fixes before attackers can take advantage of newly discovered flaws.
Google is also investing in longer-term protections, including reducing reliance on vulnerable code patterns and expanding the use of memory-safe programming languages such as Rust.
The twice-weekly Chrome security release schedule is still only a pilot, and Google has not said whether it will become permanent. But the experiment highlights a new reality for software makers: as AI accelerates vulnerability discovery, rapid patch delivery may become just as important as finding the bugs themselves.
Also read: Google plans to expand its Age Signals API worldwide, giving Android apps access to age ranges instead of exact birth dates while requiring families to opt in.