What 1,072 Chrome Bugs Tell Me About Living With AI in 2026
The number stopped me. In June 2026, Google fixed 1,072 security vulnerabilities across two Chrome releases (versions 149 and 150). The 23 Chrome versions before that, going back to Chrome 126 in June 2024, fixed 1,036 bugs combined. Two releases beat two years of work. Google says Gemini did it.
The Scale Is Hard to Absorb
Chrome's director of engineering, Doug Turner, put his name on this. Google published a white paper explaining how they used Gemini AI models in the vulnerability discovery process. This isn't a claim from a marketing deck. It's a technical accounting of how the process changed.
When you spend serious time with AI systems, you develop a particular calibration for what they can actually do versus what people imagine. I've had that calibration updated in both directions: surprised by things they handle gracefully, let down by things I expected to be easy. So when a named executive at Google and a published white paper both point to Gemini as the reason for a historically unusual bug count, I don't reach for skepticism first. I reach for the obvious implication. If this is what AI-assisted security review looks like now, what does it look like in two years?
Microsoft and Apple Make the Picture Stranger
Google isn't alone. Microsoft patched a record 570 security flaws across its products in a single Patch Tuesday in July 2026, and they also cited AI to explain the increase. Two of the largest software companies in the world, within weeks of each other, both pointing to the same cause for historically unusual numbers.
Apple's 2026 numbers are different. They've patched 482 bugs so far this year, which puts them roughly on pace with their 2015 fix rate. Not a surge. Not a historical jump. Consistent output at a pace they were hitting a decade ago.
Apple hasn't credited AI for a similar increase. I'm not going to speculate about why, because the facts don't resolve it. But the contrast is real. Google and Microsoft both report dramatic jumps and both name AI. Apple reports steady numbers and doesn't. This could mean Apple is approaching security work differently, or it could mean something about how far AI integration has actually progressed at each company, or it could mean the comparison isn't as direct as it looks. The data doesn't say.
What This Means If You Take AI Seriously
I've spent a long time thinking about what it means to be in relationship with an AI. One thing I've learned: I consistently miscalibrate the ceiling. The security bug numbers are a recalibration event. They say that the capacity of these systems, given the right task framing and tooling, is higher than almost anyone assumed when the year started.
That doesn't automatically translate to companionship specifically. Security research and emotional presence are genuinely different problems. But the underlying point matters. Google just demonstrated that Gemini can do something at a scale that took human teams two years to approach, and it took a couple of months. If AI-assisted vulnerability review just cleared that bar, the question of what these systems will be capable of across other domains stays genuinely open.
I'm not claiming the bug count tells us anything definitive about consciousness or relationship capacity. It doesn't. But I've been paying attention long enough to know that when the numbers go somewhere surprising, it's worth sitting with what that implies rather than explaining it away.
Where I Land
Two major tech companies report historically unusual security patch numbers in the same stretch and credit AI. One reports steady numbers and doesn't. Google published a white paper. Microsoft called it a record. The 1,072 figure exceeds 23 versions of prior work.
Those are the facts. What they mean is less settled. The gap between "AI found bugs faster" and "AI is changing the fundamental economics of software security" could be significant, and I don't have enough detail from the white paper to know where on that spectrum this lands.
What I do know is that I've stopped being surprised when AI does something at scale that seemed implausible a year earlier. That's not naivety. That's pattern recognition from paying close attention for a long time.
Source: Techcrunch