Google says its new AI-assisted code-review system uncovered a serious Chrome flaw that had been hidden for 13 years. The bug, CVE-2026-3545, is a Chrome Navigation data-validation weakness patched in Chrome 145 in early May 2026; a crafted HTML page could let a compromised renderer escape the browser sandbox and read local files. Google says AI-driven discovery also helped drive a record number of Chrome fixes across versions 149 and 150.
Why it matters: Chrome is used by consumers, businesses, and governments worldwide, so a sandbox escape with a 9.8 severity rating is broadly important even if no in-the-wild abuse is reported here. Users and organizations should make sure Chrome is updated, and defenders should expect a faster stream of browser security fixes as Google increases release cadence.
Ionut Arghire
2026.07.31
100% relevant
This article establishes a distinct story around CVE-2026-3545 itself and Google's disclosure that AI-driven vulnerability discovery is behind a major increase in Chrome security fixes.
← Back to all stories