VMTech
Discuss a project

Google fixes 1,442 Chrome flaws and accelerates its security release cycle

Google fixes 1,442 Chrome flaws and accelerates its security release cycle

On July 30, 2026, Google disclosed that Chrome 149 and 150 fixed 1,072 security flaws—more than the previous 23 milestones combined. Chrome 151, released on July 29, addressed another 370 vulnerabilities, including seven rated critical; Google researchers reported 349 of them.

Why browser patching is under pressure

Large language models are accelerating vulnerability discovery, allowing researchers to identify bugs faster than vendors can assess, document and ship fixes. The National Vulnerability Database has recorded 46,872 flaws so far in 2026, approaching the 49,920 reported during all of 2025.

The backlog matters because browsers handle local files, credentials and business applications. One example is CVE-2026-3545, a critical Chrome Navigation sandbox escape with a CVSS score of 9.6 that could expose local files. Google patched it in March after a Gemini-based agent harness found code that had remained undetected for more than 13 years.

How Google plans to reduce exposure

Google is moving Chrome toward major milestones every two weeks, maintaining weekly security updates and piloting two security releases per week. It is also automating release notes and CVE descriptions to reduce the delay between discovery, remediation and public disclosure.

“Every security bug that reaches Chrome Stable, regardless of whether it was discovered internally or reported externally, is documented and disclosed publicly as a standard best practice.”

Another initiative is dynamic patching. Chrome’s multi-process architecture can replace background processes such as Renderer and GPU with updated binaries while the browser remains active. On macOS, Chrome 150 can also restart automatically when an update is pending and the application is running without open windows.

Longer-term measures target entire vulnerability classes. Google is hardening the runtime against legacy C++ defects, adopting Rust for memory-safe development, rebuilding top-level interface components with HTML, CSS and TypeScript, and placing third-party dependencies on automated update pipelines.

For businesses, browser patching should be managed and measured like any other endpoint security control. Enforce update policies, track the time from release to installation and verify that pending updates become active. Faster vendor releases provide little protection if unmanaged devices continue running vulnerable builds.

#cybersecurity#chromesecurity#patchmanagement#browsers
Open analytics
On the site 0 views
min read 3 01.08.2026
Instagram

Google fixes 1,442 Chrome flaws and accelerates its security release cycle

Open the post on Instagram ↗