Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities

Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities

Image: Zulfugar Karimov/Unsplash

Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.

Aug 3, 2026

The browser security race is speeding up, and Chrome’s update calendar may be next to change.

Google is testing a new schedule that would deliver Chrome security updates twice a week as the company responds to a surge in vulnerabilities discovered through AI-powered security tools.

The move comes after Chrome 149 and Chrome 150 fixed 1,072 security bugs combined, a figure that surpassed the number of security issues patched across the previous 23 Chrome milestones, according to Google.

Google said its security teams have been using large language models to improve vulnerability discovery, bug triage and patch development. The company’s goal is to shorten the time between finding a flaw and protecting users from potential attacks.

“In the face of fast-moving, AI-powered attacks, our delivery cadence must accelerate even further. To meet this moment, we are piloting a shift to two security releases per week,” Google said in its security update report.

Google’s increased release pace is tied to improvements in AI-based vulnerability research. The company said its internal tools can now analyze Chrome’s massive codebase, identify weaknesses and help developers create fixes more quickly.

One vulnerability discovered through this process had remained hidden in Chrome’s code for more than 13 years. The sandbox escape flaw could have allowed a compromised browser process to access local files on a user’s machine.

Google said AI tools are not replacing traditional security methods but adding another layer alongside techniques such as fuzzing and external vulnerability research programs. The company is also seeing more security reports from researchers. Google said it received more external bug reports in March 2026 than it received throughout all of 2025, increasing pressure to process and fix vulnerabilities faster.

Google wants Chrome updates to become less annoying

The biggest challenge with faster security releases is not only creating patches but getting them installed.

Chrome already downloads and prepares updates in the background, but users typically need to restart the browser before security fixes take effect. Google said this delay creates a “patch gap” where attackers may have time to study vulnerabilities after fixes become public.

Advertisement

To address this, Google is exploring dynamic patching, a system designed to replace updated browser components without requiring a full restart.

The company has also introduced a “zero window auto-restart” feature in Chrome 150 on macOS. It allows Chrome to automatically restart and apply updates when the browser has no open windows but is still running in the background. Google has not announced when dynamic patching will become available to all Chrome users.

More Google coverage

What faster Chrome releases mean for businesses

The change will likely happen quietly for consumers. Chrome already updates automatically for most users, and Google is working to reduce the need for manual restarts.

Businesses, however, may face new challenges. Organizations that manage large Chrome deployments will need to balance faster security protection with the need to test browser updates before widespread rollout.

A twice-weekly security cycle could require IT teams to rethink update policies, especially in industries where browser compatibility is critical for daily operations. Google recommends enterprise customers use Chrome management tools, update policies, and monitoring systems to keep devices protected.

Advertisement

The bigger security shift

Google’s move shows how AI is changing the balance of software security. In the past, discovering vulnerabilities was often the biggest hurdle. Now, companies increasingly need to deliver fixes before attackers can take advantage of newly discovered flaws.

Google is also investing in longer-term protections, including reducing reliance on vulnerable code patterns and expanding the use of memory-safe programming languages such as Rust.

The twice-weekly Chrome security release schedule is still only a pilot, and Google has not said whether it will become permanent. But the experiment highlights a new reality for software makers: as AI accelerates vulnerability discovery, rapid patch delivery may become just as important as finding the bugs themselves.

Also read: Google plans to expand its Age Signals API worldwide, giving Android apps access to age ranges instead of exact birth dates while requiring families to opt in.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.