{"slug": "google-wants-to-update-chrome-without-a-full-browser-restart", "title": "Google wants to update Chrome without a full browser restart", "summary": "Google announced plans to update Chrome without requiring a full browser restart, using a technique called dynamic matching that replaces background child processes with updated binaries on the fly. The Chrome team is also exploring seamless session restore and automatic restarts on macOS when no windows are open, ahead of a two-week update cycle later this year. Google reported that in Chrome 149 and 150, it fixed 1,072 security bugs, surpassing the total from the prior 23 milestones combined, aided by LLM-based bug finding and multi-agent fix workflows.", "body_md": "Google today is out with a [lengthy post](https://blog.google/security/) describing the role of AI and LLMs in Chrome security.\n\nWhile it takes Google 1-2 days to triage, fix, test, and release a patch, the “time spent waiting for the user to restart Chrome can be a significant contributor to N-day exploitation risk,” or the patch gap.\n\nAcknowledging the burden of having to restart, Google is investing in “dynamic matching” to “eliminate the need for a full browser restart in most cases.” It works by replacing “background child processes (like the Renderer and GPU) with updated binaries on the fly.” This approach leverages Chrome’s multi-process architecture.\n\nThe Chrome team is still researching and developing this feature. Google is also “exploring ways to ensure a seamless session restore even in complex cases, by saving more state locally.” This will become more important when Chrome moves to its [two-week update cycle](https://9to5google.com/2026/03/03/chrome-two-week-updates/) later this year.\n\nUntil then, Google is looking for “opportune moments to restart automatically, when we can guarantee a seamless session restore.” In Chrome 150 for Mac, Google will restart the browser automatically when there’s a pending update and no open user windows.\n\nFor example, in Chrome 150, we rolled out a change to take advantage of the unique application state on macOS where applications typically continue running in the background even after all windows are closed.\n\nGoogle also discussed its latest use of LLMs to find bugs, with the process starting in 2023. Earlier this year, it created an agent harness that uses Gemini and other models to “find vulnerabilities across the broader Chrome codebase with higher efficiency and lower false positives.” One notable find was a bug that had been in the codebase for 13 years.\n\nIn terms of safety, some interesting process details were shared:\n\n- “Our AI analyzes source code strictly at rest, operating on locked-down machines that lack general internet access.”\n- “We also utilize a dedicated setup for these internal scans that intercepts all network requests, employing strict allowlists based on the initiating application and destination, blocking any suspicious model activity.”\n- “Furthermore, we never run models in an unrestricted mode, and we strictly limit our subagents from modifying the local system or accessing files outside of designated source code directories.”\n- “We have partnered closely with Google DeepMind and Project Zero for years, including on BigSleep and CodeMender. These tools are natively integrated into our continuous integration (CI) system, running every 24 hours across all CLs to proactively detect security bugs. This integration has yielded significant results: in May alone, we blocked over 20 vulnerabilities from reaching production, including a critical S1+ issue.”\n\nTo fix vulnerabilities, there’s now a multi-agent workflow, with LLMs generating candidate fixes for most of them:\n\n- After initial build steps that bring in context from a specific issue, we run a fixing agent that returns multiple candidate fixes.\n- A critic agent then evaluates which would be the best fit, producing other relevant artifacts for developers to evaluate the fix.\n- The fixing and critic agents work in a loop that mimics a typical code review process to ensure that code is functional and compliant with Chromium and Google style guidelines, as well as other local code conventions.\n- Test-writing agents help write tests for fixes. These agents can ensure that tests work across the full array of Chrome supported platforms and configurations before a developer reviews the fix, saving up to weeks of developer time.\n\nThis process has resulted in a dramatic increase in security fixes:\n\nIn the last two milestones, Chrome 149 and 150, we have fixed 1072 security bugs, surpassing the total number of security bugs fixed across the prior 23 milestones combined.\n\n*FTC: We use income earning auto affiliate links.* [More.](https://9to5mac.com/about/#affiliate)\n\n[our homepage](http://9to5google.com/)for all the latest news, and follow 9to5Google on\n\n[exclusive stories](https://9to5google.com/feature/exclusive/),\n\n[reviews](https://9to5google.com/guides/reviews/),\n\n[how-tos](https://9to5google.com/guides/how-to/), and\n\n[subscribe to our YouTube channel](https://www.youtube.com/9to5google)", "url": "https://wpnews.pro/news/google-wants-to-update-chrome-without-a-full-browser-restart", "canonical_source": "https://9to5google.com/2026/07/30/chrome-security-ai-llm/", "published_at": "2026-07-30 17:00:00+00:00", "updated_at": "2026-07-30 18:12:37.125149+00:00", "lang": "en", "topics": ["artificial-intelligence", "large-language-models", "ai-safety", "ai-tools", "developer-tools"], "entities": ["Google", "Chrome", "Gemini", "Google DeepMind", "Project Zero", "Chrome 150", "macOS"], "alternates": {"html": "https://wpnews.pro/news/google-wants-to-update-chrome-without-a-full-browser-restart", "markdown": "https://wpnews.pro/news/google-wants-to-update-chrome-without-a-full-browser-restart.md", "text": "https://wpnews.pro/news/google-wants-to-update-chrome-without-a-full-browser-restart.txt", "jsonld": "https://wpnews.pro/news/google-wants-to-update-chrome-without-a-full-browser-restart.jsonld"}}