Chrome 152 Patches 327 Security Flaws, Most Found by Google's Own AI

Google's largest Chrome update fixes hundreds of vulnerabilities at once, with its own AI tools responsible for the overwhelming majority of discoveries.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A computer workstation surrounded by multiple monitors displaying code snippets, vulnerability alerts, and security patch notes, with a single red vulnerability
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Google released Chrome 152 on Tuesday, patching 327 security vulnerabilities, the largest single update in recent memory.
  • Ten flaws carry a "critical" severity rating, meaning attackers could use them to take over a victim's browser or device.
  • 299 of the 327 bugs were found by Google's own internal teams using artificial intelligence tools.
  • An external researcher named Goodluck earned a $25,000 reward for reporting the single most serious externally discovered flaw, tracked as CVE-2026-79282.
  • Google says none of the fixed flaws are being actively used by criminals right now.

Google pushed out Chrome 152 on Tuesday with patches for 327 security vulnerabilities. That number would have seemed extraordinary even two years ago, and it reflects how much artificial intelligence tools, programs trained to spot coding mistakes automatically, have changed the pace of security research.

What exactly was wrong with Chrome?

All ten critical-severity flaws are a class of bug called use-after-free, where a piece of the browser's memory gets reused in a way the code never intended, letting an attacker run their own instructions on your computer. Affected components include graphics handling (Angle), the desktop window manager (Aura), Chromecast streaming, the browser's interface layer (Views), and Safe Browsing, the feature that warns you about dangerous websites.

The rest are medium or low risk. Of the 327 total, 299 were found internally by Google.

Severity Count Example component
Critical 10 Angle, SafeBrowsing
Found by AI internally 299 Google internal

We've tracked the use-after-free class of bug across six stories in the past 90 days, and the pattern is consistent: AI finds volume, humans find the highest-value individual flaws.

Should ordinary Chrome users be worried?

Not if you update today. Google confirmed no criminal group was exploiting any of these flaws before the patch shipped. Bugs that attackers know about before a fix exists are the most dangerous kind; once Chrome updates, the holes are closed.

Chrome usually updates itself in the background. To confirm yours is current, open the three-dot menu in the top-right corner, click "Help," then "About Google Chrome." The browser will install any pending update and prompt you to relaunch.

Researcher Goodluck reported the most serious externally found flaw, CVE-2026-79282, earning $25,000 through Google's bug-bounty programme, a scheme that pays independent security researchers to report flaws rather than sell them elsewhere. Several other researchers received smaller payouts for additional discoveries in this same release.

Google has now fixed well over 2,000 Chrome vulnerabilities this year, a pace driven almost entirely by AI-assisted internal scanning. External researchers still deliver the highest-value individual finds, but the volume belongs to the machines. The practical upshot for anyone running Chrome: a browser restart is all that's required.

© 2026 Threat Vectr