Google reports record volume of security patches enabled by large language models
Internal data reveals a sharp shift in the speed of vulnerability discovery as automated tools allow engineers to outpace traditional security cycles and adversarial threats.
Julian Reeve
Jul 30, 2026 · 1 min read
One thousand and seventy-two security flaws were patched in the two versions of Chrome released in June, a volume that exceeds the total number of fixes issued for the browser over the previous two years. The surge in productivity marks a transition from manual oversight to an industrial-scale operation for software defense. Google revealed the data as part of a broader study on how large language models have altered the economics of cybersecurity, effectively automating the discovery of vulnerabilities that were previously invisible or too resource-intensive to track.
The scale of the shift is significant. The previous 23 versions of Chrome required 24 months to address 1,036 bugs, a figure now eclipsed by a single month of AI-assisted engineering. This acceleration is not isolated to one ecosystem. Microsoft recently reported a record 570 patches across its product lines during a single update cycle, citing its own implementation of automated discovery tools. In both cases, the companies are responding to a structural change in the threat landscape, where the same technologies are being used by outside actors to probe for weaknesses at high speed.
While the automation of defense allows for a more resilient software stack, the distribution of these gains is uneven. Independent counts of Apple’s security releases for 2026 suggest its patching cadence remains consistent with historical norms, roughly matching levels seen a decade ago. The discrepancy highlights a divergence in technical strategy among the world’s largest software providers as they decide whether to integrate generative models into the core of their maintenance pipelines or maintain traditional human-led review processes.