If Chrome has felt like it’s updating more often than usual, there’s a concrete reason. Google disclosed this week that the two Chrome versions released in June (milestones 149 and 150) fixed 1,072 security bugs. That exceeds the total fixed across the previous 23 versions over roughly two years (1,036).

The driver is large-scale use of large language models—primarily engineered versions of Gemini—across the vulnerability lifecycle: discovery, triage, candidate patch generation, and test creation. Doug Turner, Chrome’s director of engineering, put it bluntly: LLMs have “fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation.”

This isn’t isolated. Microsoft’s July 2026 Patch Tuesday hit a record 570 vulnerabilities, with the company also pointing to AI-assisted discovery as a major factor in the volume increase. Google has been building toward this for years (fuzzing improvements, Project Zero’s Naptime and Big Sleep work, and more recent Gemini-powered agents that scan the broader codebase with lower false-positive rates). One notable find was a sandbox-escape bug that had sat in the code for more than 13 years.

Why the surge is both good news and a warning

On the positive side, more bugs are being found and fixed before they reach users, and Google is responding by accelerating delivery—piloting two security releases per week and exploring dynamic patching that could reduce the need for full browser restarts.

The harder reality is the arms race. The same class of models that help Google hunt and patch at industrial scale are available to attackers hunting zero-days. Browser codebases keep growing more complex (AI features, extensions, web platform surface area), which expands the attack surface even as detection improves. And while Chrome gets more secure against remote code execution and sandbox escapes, its default data practices—account sync, browsing data for ads and personalization, extensive telemetry—remain unchanged.

In short: the defensive side is getting faster, but the underlying product is still a high-value target that collects a lot of data by design.

What this means for users who care about privacy

Relying solely on rapid patching of a complex, data-hungry browser is incomplete protection if your threat model includes tracking, profiling, or local data exposure. For high-sensitivity use (banking, work documents, private communications) on Android, a purpose-built privacy browser that prioritizes local isolation can complement the mainstream options.

Incognito Browser is designed around that model:

  • Sessions stay local—no history, cookies, or session data synced to external servers.
  • Automatic purge of cache and session data when you exit or minimize the app.
  • Aggressive blocking of trackers, fingerprinting scripts, and analytics.

If you want to reduce the digital footprint that both trackers and opportunistic attackers can leverage, a zero-trace, locally sandboxed browser is one practical step. You can find it on Google Play.

Browser phone