Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting (www.wired.com)

🤖 AI Summary
Google's Chrome browser has ramped up its security patching frequency, now issuing updates twice a week due to a surge in vulnerabilities detected through AI-based bug hunting. In a report from the Chrome security team, June's major version releases fixed 1,072 security bugs, surpassing the total from the previous 23 releases. This dramatic increase is attributed to advancements in Chrome’s internal processes for utilizing AI tools in vulnerability discovery and triage, underscoring a significant shift in how software security is approached. The integration of AI has enabled the Chrome team not only to find and fix vulnerabilities at an unprecedented rate but to analyze the entire codebase history for potential weaknesses, including legacy features that typically receive less scrutiny. As the landscape evolves, Chrome is exploring longer-term structural changes, such as transitioning parts of its codebase to more secure programming languages like Rust. Despite the current spike in vulnerabilities, Chrome's team acknowledges that this phase may not last indefinitely, suggesting a future equilibrium where the workflow incorporates AI as a standard practice in software security development.
Loading comments...
loading comments...