What the number says
On Google's security blog, Chrome versions 149 and 150 closed 1,072 security bugs, against 1,036 across the previous 23 versions over two years. The company attributes the jump to internal AI tools, including Gemini models. Doug Turner, Chrome's director of engineering, describes large language models as turning vulnerability discovery into an automated, industrial-scale operation.[1]
That number measures the count of bugs found and closed. It does not measure how many remain in the Chrome browser. A rising figure can mean better searching, a growing codebase, or both; the announcement offers no estimate of what is left. So on its own, 1,072 does not say the browser is safer today than it was yesterday.[1]
Why the comparison helps
A number standing alone is hard to read and easy to read next to its neighbours. Microsoft patched 570 flaws in July 2026 using AI tools. Apple shows no comparable jump: the 482 bugs it fixed across 2026 track its historical rate.[1]
That divergence is consistent with a difference in tooling, but tooling is not the only account. The companies differ in how much they disclose separately, in codebase size and in release calendars; the three numbers are not measured on a common denominator. Apple running comparable tooling and simply not publishing per-release breakdowns would produce the same picture.[1]
The only lever in the user's hands
A closed hole only starts protecting a user after the browser updates and restarts. Every postponed restart leaves part of those 1,072 patches sitting unused. Two concrete signals are worth watching over the coming months: whether the Chrome release cadence changes, and whether the company begins separating out how many of each release's fixes came from AI tools. If the second appears, the number a user reads turns into information about direction for the first time.[1]