Google AI uncovers 13-year-old Chrome flaw amid record patching pace

1 hour ago 1



A vulnerability hiding in Chrome’s code since 2013 just got found by a machine. Google’s AI-driven vulnerability detection system, built on its Gemini model, identified a high-severity flaw designated CVE-2026-3545. The bug lives inside Chrome’s Navigation component and qualifies as a sandbox escape, meaning an attacker could use it to break out of the browser’s protective isolation layer and reach the underlying operating system. Its CVSS score is 9.8 out of 10. A 13-year guest that nobody invited The flaw was patched in Chrome version 145, released in early May 2026, but the code it exploits had reportedly been sitting there since around 2013. The AI agent that found it uses a combination of a historical CVE database and Git commit history to methodically trace how code has evolved over time, running its analysis on restricted machines that process inactive code in isolation. Google was careful to frame the AI system as complementary rather than a replacement. The team noted that fuzzing, human researchers, and external reports all remained active contributors to Chrome’s security posture in 2026, with external submissions actually rising enough to prompt adjustments to the Chrom...

Read Entire Article