{"slug": "google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app", "title": "Google's AI Agent Big Sleep Found a Chrome Bug That Predates the iPhone's App Store", "summary": "Google's Chrome Security Team reported that AI systems helped push through 1,072 security fixes in Chrome 149 and 150, including a sandbox escape that had remained in the codebase for over 13 years. The fixes were attributed to a Gemini-powered agent harness built in early 2026, building on the Big Sleep collaboration with DeepMind and Project Zero. Google says automation is saving hundreds of developer hours monthly and blocked over 20 vulnerabilities from reaching production in May alone.", "body_md": "*Google's Chrome security team says AI systems helped it push through 1,072 security fixes in Chrome 149 and 150, including one sandbox escape that had sat in the codebase for more than 13 years.*\n\nA Chrome bug that lets a compromised renderer trick the browser into reading local files is not a small miss. It's the kind of flaw the sandbox exists to contain. Google's point, in a security post published on July 30, 2026, is that this one stayed buried in Chromium for more than 13 years before a Gemini-powered agent harness found it in early 2026.\n\nThat detail matters because Chrome is not some neglected side project. It's one of the most watched pieces of consumer software in the world, picked over by Google's own engineers, outside bug bounty hunters, fuzzers and rival security teams. If an AI system can still surface a sandbox escape from old code, you should assume other mature codebases have the same problem sitting quietly inside them.\n\n## The Bug Count Changed Fast\n\nAccording to Google's Chrome Security Team, Chrome 149 and 150 fixed 1,072 security bugs, more than the total across the prior 23 milestones combined. That isn't a rounding error. Chrome 150 alone was promoted to the stable channel on June 30, 2026, and Google's release notes listed 433 security fixes for the desktop build. Malwarebytes separately covered the same Chrome 150 release on July 1 and counted 382 security fixes in the user-facing update, including 15 critical issues.\n\nThe exact accounting differs by platform and release view, but the direction is clear. Chrome's security queue got much heavier at once.\n\nGoogle tied the surge to several pieces of its internal pipeline. In 2025, it worked with DeepMind and Project Zero on Big Sleep, an AI vulnerability discovery agent that Google says found bugs in V8 and the graphics stack. In early 2026, the Chrome team then built a broader Gemini-based agent harness for the Chrome codebase, with the goal of finding vulnerabilities more efficiently and with fewer false positives. That's the system Google connects to the 13-year-old sandbox escape.\n\nThe original draft went too far by saying Big Sleep itself found that Chrome sandbox bug. Google's post doesn't say that. It says the broader Gemini agent harness found it, while Big Sleep was part of the longer collaboration with DeepMind and Project Zero. That's a meaningful distinction. Security attribution has to be exact.\n\n## The Work After Discovery Is The Real Test\n\nFinding a bug is only the first part of the job. Google says it has also used AI to help triage reports, filter out spam and duplicates, reproduce proof-of-concept exploits, attach metadata such as severity ratings and route issues to the right human owner. Historically, Google said, triaging a single security report took anywhere from five to more than 30 minutes. Multiply that by hundreds of reports and you get the actual bottleneck.\n\nThis is where the story becomes more useful for you if you run software teams. The flashy number is 1,072. The operational change is that Google says automation is now saving hundreds of developer hours a month. It also says BigSleep and CodeMender are integrated into Chrome's continuous integration system and run every 24 hours across change lists. In May alone, Google said that setup blocked more than 20 vulnerabilities from reaching production, including a critical S1+ issue.\n\nThat is the part competitors will copy first. Not the blog post. The plumbing.\n\nWIRED reported on July 30 that Chrome is already moving toward major releases every two weeks, with additional weekly security updates, and is piloting two security releases per week while this AI-driven bug spike works through the system. The Verge also noted that Google is researching dynamic patching, so Chrome can apply many fixes without forcing a full browser restart. That sounds dull until you remember why the restart matters: once a fix is visible in open source code, attackers can reverse engineer it before every user has applied the update.\n\nGoogle calls that the patch gap. You can call it the dangerous waiting room between a public fix and an actually protected user.\n\nNone of this means human security researchers are finished. Don't bother with that easy conclusion. Google's own post keeps humans in the loop for severity decisions, ownership and code review, and WIRED reported that Chrome leaders still expect structural work, including Rust rewrites for some older C++ components, to matter alongside AI-assisted discovery.\n\nThe stronger conclusion is narrower. AI is now good enough to change the economics of vulnerability management - not just at the margins, but in the hard daily work of finding bugs, sorting them and shipping fixes at Chrome scale. It can also pile more pressure on users and IT departments that already dislike constant browser restarts. Worth knowing.\n\nGoogle hasn't said the 13-year-old sandbox escape was exploited in the wild. That absence matters. Until there is evidence either way, the honest reading is simple: Chrome found and fixed a long-lived flaw, but the industry now has to live with the awkward question its discovery raised.\n\nIf this can happen inside Chrome, it can happen anywhere.\n\n**Also read:** [Congress presses DoorDash to disclose its use of a Chinese AI model](https://startupfortune.com/congress-presses-doordash-to-disclose-its-use-of-a-chinese-ai-model/) and [MiniMax's H3 Video Model Undercuts Sora and Veo on Price and Openness](https://startupfortune.com/minimaxs-h3-video-model-undercuts-sora-and-veo-on-price-and-openness/) and [Zhipu AI stays silent as reports point to a trillion-parameter GLM-5.5](https://startupfortune.com/zhipu-ai-stays-silent-as-reports-point-to-a-trillion-parameter-glm-55/)", "url": "https://wpnews.pro/news/google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app", "canonical_source": "https://startupfortune.com/googles-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphones-app-store/", "published_at": "2026-08-03 14:18:56+00:00", "updated_at": "2026-08-03 14:48:24.279538+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-tools", "ai-research"], "entities": ["Google", "Chrome Security Team", "Chrome", "Gemini", "Big Sleep", "DeepMind", "Project Zero", "Malwarebytes"], "alternates": {"html": "https://wpnews.pro/news/google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app", "markdown": "https://wpnews.pro/news/google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app.md", "text": "https://wpnews.pro/news/google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app.txt", "jsonld": "https://wpnews.pro/news/google-s-ai-agent-big-sleep-found-a-chrome-bug-that-predates-the-iphone-s-app.jsonld"}}