Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • Google AI Supercharges Chrome Security, Fixing 1,072 Bugs Pierluigi Paganini
    Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team fixed 1,072 security bugs, more than the total fixed across the prior 23 milestones combined. That’s not a marginal improv
     

Google AI Supercharges Chrome Security, Fixing 1,072 Bugs

31 de Julho de 2026, 10:46

Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching

Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team fixed 1,072 security bugs, more than the total fixed across the prior 23 milestones combined. That’s not a marginal improvement. That’s a different category of operation.

“In early 2026, we built an agent harness that used Gemini to find vulnerabilities across the broader Chrome codebase with higher efficiency and lower false positives. One of the bugs we found was a sandbox escape that would allow a compromised renderer to trick the browser into reading local files — a bug that quietly survived in our codebase for more than 13 years!” states Google. “For many of us, this moment cemented the potential of AI-powered vulnerability detection.”

The same tools that find bugs are now also triaging them. Historically, triaging a single security report took between 5 and 30 minutes of human time. The automated system now handles filtering duplicates, reproducing the bug, assigning severity, and routing it to the right team — the Chrome team estimates this is saving hundreds of hours of developer time per month.

Fixing bugs at scale required rethinking the entire repair pipeline. The current approach runs a fixing agent that produces multiple candidate patches, a separate critic agent that evaluates which is best, and a test-writing agent that verifies the fix works across all Chrome platforms before a human ever reviews it.

“We have partnered closely with Google DeepMind and Project Zero for years, including on BigSleep and CodeMender. These tools are natively integrated into our continuous integration (CI) system, running every 24 hours across all CLs to proactively detect security bugs.” continues the IT giant. “This integration has yielded significant results: in May alone, we blocked over 20 vulnerabilities from reaching production, including a critical S1+ issue.”

The external vulnerability reward program also saw a sharp increase: by March 2026, Chrome received more bug reports than it had in all of 2025, which prompted a change to the VRP to focus researchers on findings that add something beyond what internal AI tools are already catching.

The speed at which fixes reach users matters as much as the speed at which bugs are found.

“Once a fix has landed and is visible in the public open source codebase, attackers can start to reverse engineer and exploit the bug before the fix reaches users’ machines — so called “N-day” attacks.” states Google. “This is commonly referred to as the “patch gap.” Since fixes committed to the main “tree” typically take weeks to reach the Chrome Stable channel (what the vast majority of our users run), minimizing this patch gap is a critical part of our strategy.”

Even that cadence isn’t enough if users don’t restart their browser to apply the update, which most people delay for understandable reasons. Chrome is now working on dynamic patching that replaces background processes on the fly without requiring a full restart, and has already shipped a change in Chrome 150 that automatically restarts the browser on macOS when all windows are closed and an update is pending.

The longer-term structural work is about eliminating entire bug categories rather than patching individual instances. Chrome is expanding MiraclePtr, a technology that neutralizes use-after-free vulnerabilities, to more libraries including Skia, ANGLE, and Dawn, with a goal of covering up to 90% of UAF bugs on the GPU main thread. A separate “spanification” effort has already brought 97% of first-party Chrome code to compile cleanly with strict unsafe-buffer warnings — pushing spatial safety enforcement into the compiler rather than relying on runtime checks. The honest admission in the post is that runtime mitigations have a ceiling, and the long-term answer is rewriting high-risk components in Rust. Chrome is building a centralized Rust SDK to make that a routine engineering choice rather than a heroic one.

The scale of the dependency problem is worth stating plainly. Chrome has more than 2,300 third-party dependencies across Chromium and satellite projects, about 1,700 of which ship to users in products ranging from Android devices to cloud enterprise stacks. All of those are now being moved onto automated update pipelines that roll them to their latest upstream versions continuously, with safety signals from Google’s Open Source Security Intelligence Platform providing guardrails against introducing new problems in the process.

“The AI era has undeniably intensified the software security threat landscape, but by combining rapid deployment mechanisms with deep structural defenses, we are ensuring the advantage remains firmly with defenders. With this, Chrome and the broader web become safer with every update.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

  • ✇Security Affairs
  • Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices Pierluigi Paganini
    EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and one for blocking app developers from directing users to cheaper alternatives outside the Play Store. These are Google’s first DMA fines, but the
     

Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices

24 de Julho de 2026, 17:47

EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny.

The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and one for blocking app developers from directing users to cheaper alternatives outside the Play Store. These are Google’s first DMA fines, but the fifth and sixth competition penalties against the company overall, bringing the cumulative total to €10.38 billion over nearly two decades. At this pace, Google is basically funding a small member state.

“Today, the European Commission took two decisions finding non-compliance by Google with the Digital Markets Act (DMA) for self-preferencing its own services on Google Search, and for putting in place restrictions on businesses to direct consumers to alternative, often cheaper, purchase channels on Google Play (steering).” reads the press release published by the European Commission. “In this regard, the Commission issued Google a fine of €460 million and a fine of €430 million respectively.”

The search fine covers Google’s handling of shopping, hotels, transport, and sports results, where the Commission found the company systematically promoted its own products over rivals. The Play Store fine targets steering restrictions that prevented developers from telling users they could buy the same app or subscription elsewhere for less.

Despite the scale of the penalties, the Commission signaled that ongoing daily fines for non-compliance are unlikely.

“The Commission notes that, after a constructive dialogue, Google has proposed and started testing changes to how it presents its own services on Google Search for free services such as shopping, hotels and flights.” EU continues. “The Commission will monitor the implementation of these solutions which constitute substantial progress towards compliance.”

The Commission described this as substantial progress and flagged a “constructive dialogue” with Google, which is regulatory language for “we’re not done but we’re not going to war either.”

Google has 60 days to comply with orders to treat rivals fairly and allow developers to redirect users away from the Play Store. The company rejected the findings and didn’t rule out taking the Commission to court. President of Global Affairs Kent Walker argued that complying would force Google to strip out real-time search features like hotel pricing and flight availability, and remove safety protections from the Play Store, framing the decisions as harmful to European users rather than protective of them.

“The Commission also notes that Google has proposed and started testing changes to how it presents shopping ads and content related services, such as sports.” states the press release. “The Commission is currently assessing these changes and will continue its dialogue with Google in light of today’s decision.”

That extension to AI features is the part of this decision that will matter most in the long run, as AI-generated summaries are increasingly becoming the first layer of search results that users interact with. The fines are the third under the DMA after Apple and Meta were penalized in April last year, and the U.S. government’s response was predictable.

Reuters reported that trade Representative Jamieson Greer said the actions are “driving massive uncertainty for U.S. exports.” though no specific retaliatory measures were announced.

“The two non-compliance decisions were adopted after a thorough investigation, including feedback from market participants, and extensive dialogue with Google.” concludes the press release. “When calculating the fines, the Commission has assessed the gravity, duration and recurrence of the breaches and concluded that the level of fines imposed are proportionate and appropriate.

Google may challenge today’s decisions in court.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, EU)

  • ✇Security Affairs
  • Europe Confirms Record €4.1B Penalty Against Google for Android Practices Pierluigi Paganini
    EU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices. The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brought by Google and its parent company Alphabet against an earlier judgment from the General Court, confirming a fine of €4,125,000,000. Alphabet is jointly and severally liable for €1,520,605,895 of that amount. The case goes ba
     

Europe Confirms Record €4.1B Penalty Against Google for Android Practices

2 de Julho de 2026, 14:29

EU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices.

The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brought by Google and its parent company Alphabet against an earlier judgment from the General Court, confirming a fine of €4,125,000,000. Alphabet is jointly and severally liable for €1,520,605,895 of that amount.

The case goes back to 2018, when the European Commission concluded that Google had abused its dominant market position through three categories of restrictions built into its Android licensing arrangements. Device manufacturers who wanted access to Google’s Play Store had to pre-install Google Search and Chrome. To get the licences needed for those apps, they also had to agree not to sell devices running Android versions that Google hadn’t approved. And Google paid manufacturers and mobile operators a share of its advertising revenue on the condition that they didn’t pre-install a competing search engine on a defined set of devices. The Commission concluded all three formed a single, coordinated strategy to protect Google’s search dominance, and fined the company €4,342,865,000.

The General Court reviewed the case in 2022 and agreed that the conduct was a single and continuous infringement. It annulled one piece of the Commission’s decision: the part dealing with revenue share agreements tied to the exclusive pre-installation of Google Search on a predefined device portfolio. That partial annulment led the court to recalculate the fine downward to €4.125 billion. Everything else held.

Google and Alphabet then appealed to the Court of Justice, the EU’s highest court, arguing the General Court had made legal errors in its analysis. The Court of Justice went through those arguments and rejected them all.

“The appeal brought by Google and its parent company Alphabet against the judgment of the General Court is dismissed, thereby confirming the penalty imposed for Google Search’s abuse of a dominant position in the context of the Android operating system.” the court’s press release states. “In 2018, the European Commission adopted a decision in which it concluded 1 that Google had abused its dominant position by requiring, in particular through pre-installation agreements and licensing conditions for certain apps, that its search engine, Google Search, and its Chrome browser be promoted on mobile devices running the Android operating system, which is also provided by Google. 2 It therefore found a single and continuous infringement covering the whole of that conduct and imposed an overall fine on Google of €4 342 865 000, with Alphabet jointly and severally liable as to €1 921 666 000.”

Google’s first argument was that the General Court assessed the anticompetitive effects of the pre-installation conditions incorrectly, in particular, that it should have run a counterfactual analysis to show what the market would have looked like without those conditions. However, the Court of Justice disagreed and confirmed the General Court was entitled to look at the full economic context, including the revenue share agreements, without needing to run a formal counterfactual test. The court also confirmed the finding that pre-installed apps enjoy a status quo bias, meaning users are less likely to switch away from them, and that Google hadn’t shown that user preferences or the quality of its services alone explained its market position.

On the pre-installation conditions specifically, Google argued that proving abuse of a dominant position requires showing the conduct could exclude competitors that are equally efficient. The Court of Justice rejected that too.

“Second, the General Court did not err in law by confirming the Commission’s assessment of the pre-installation conditions laid down by the Android agreements. Demonstrating an abuse of a dominant position is not conditional in any case on proof of a capability to foreclose only as-efficient competitors.” continues the press release. “Given the particular characteristics of the digital markets concerned, the General Court was entitled to conclude that those practices were liable to restrict competition and strengthen barriers to entry without applying that test.”

On the anti-fragmentation agreements, which required manufacturers to avoid selling devices running unapproved Android forks, the Court of Justice again sided with the General Court. Those agreements limited the commercial space for Android versions Google hadn’t blessed, which reinforced its dominant position. A counterfactual analysis wasn’t necessary because the anticompetitive effects were already sufficiently established on the facts.

Google also challenged how the fine was calculated, invoking procedural arguments including rights of defence. The Court of Justice endorsed the General Court’s use of its unlimited jurisdiction to set the penalty amount, ruling that the reasoning was sufficient and the procedural principles were respected.

“The Court of Justice endorses the exercise by the General Court of its unlimited jurisdiction to set the amount of the fine, ruling that its reasons were sufficient and that the procedural principles invoked by Google and Alphabet, including rights of defence, were adhered to.” states the report.

Google is disappointed with the ruling.

“We are disappointed with the ruling. Android has given people more choice, not less, enabling thousands of device makers to build affordable smartphones and giving billions of people access to a wide range of apps and services. We will review the judgment carefully.” the company said in a statement.

This is the end of the road for this particular case. The Court of Justice is the EU’s highest court on points of law. There’s no further appeal. The €4.1 billion fine stands, and the legal framework the Commission used to reach that conclusion has now been validated at every level of the EU court system.

The case also sets a precedent for how digital markets get treated under EU competition law. The court confirmed that the standard test used in traditional markets, whether conduct excludes equally efficient competitors, doesn’t automatically apply in digital contexts. That has implications well beyond Google. Any company with a dominant platform position in the EU now knows that structuring licensing arrangements to steer users toward its own products carries real legal risk, even if it can argue its products are genuinely better.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

❌
❌