Gemini agent digs a 13-year-old sandbox escape out of Chrome's code

Google announced Thursday that its AI tools helped to fix 1,072 security bugs across the two versions of Chrome it shipped in June. That’s more than the previous 23 releases of the browser combined.
One of those tools also found a sandbox vulnerability that had been hiding in the code for over 13 years.
Google’s AI found a Chrome sandbox bug hidden since 2013
The count of 1,072 includes Chrome 149 and Chrome 150, both released last month. The 23 stable releases Google has shipped over the last two years contained a total of 1,036 fixes.
Large language models have “fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation,” said Doug Turner, Chrome’s director of engineering. Models like Gemini allow the team to “preemptively” fix flaws and get ahead of attackers, he said.
The company said that “an increase in bugs found and fixed is not a sign of failure.”
In early 2026, Google built a Gemini agent harness to sift through the wider Chrome codebase. That system found a sandbox escape that was in the code for over 13 years. The flaw, if unpatched, could allow a compromised renderer process to trick the browser into reading local files, Google said.
… Continue reading the full article at the original source below.
Related
Bitcoin ETFs Post $233M in Inflows, Pushing the Week Back Into the Green
Novo Nordisk (NVO) Stock: Plunges 9% After ZEUS Heart Trial Misses Key Goal
BP puts UK North Sea oil and gas assets up for sale after 60 years of production