The Industrialization of Vulnerability Discovery

Google has fundamentally altered its security patching cadence by integrating Large Language Models (LLMs) into its vulnerability discovery pipeline. In June 2026, the company patched 1,072 security bugs across two Chrome releases. For context, this single month of activity exceeded the 1,036 bugs patched over the previous 23 releases spanning two years.

According to Doug Turner, Chrome’s director of engineering, this shift represents a move toward "automated, industrial-scale operation." By utilizing models like Gemini, Google is now able to preemptively identify and remediate vulnerabilities at a speed that significantly outpaces traditional manual discovery methods.

This trend is not isolated to Google. Microsoft recently reported a record 570 security patches in a single month, explicitly attributing the surge to AI-assisted discovery. However, the adoption of these tools is not uniform across the industry. Apple, for instance, has not demonstrated a similar exponential increase in patch volume, with its 2026 fix rate remaining consistent with historical data from 2015.

This divergence suggests that while AI is becoming a critical tool for defenders, the efficacy of these systems depends heavily on the integration of LLMs into existing development and security workflows. As AI-powered systems make vulnerability discovery exponentially faster, cybersecurity teams are increasingly forced to adopt similar AI-driven defensive measures to maintain parity with both automated security tools and potential adversaries.