4 ms·
Not that I don't believe its possible to fix a lot of bugs, I also wonder what the actual dynamic was. Were the people in team working much more than usual as w
by truncate 2mo ago
Not that I don't believe its possible to fix a lot of bugs, I also wonder what the actual dynamic was. Were the people in team working much more than usual as well? Given its Google, I wouldn't be surprised if there was an "internal push" to fix more bugs over next X sprints so that they can publish this blog and some manager can show impact and AI adaption to his superior.
- brador 2mo agoMore likely just getting ahead of the AI attacks before they hit. The threat risk increase caused by AI has gone off the chart.
- deeringc 2mo agoExactly this. And there are few bigger targets than Chrome when it comes to finding exploits (OSes and network equipment are probably on par). I'm sure they have devoted large compute resources and human staffing at making sure that they find and fix these issues before anyone else does.
- nevi-me 2mo ago1. Our backlog of bugs gets processed quicker because instead of staring at the code for 10 minutes fiuring out what's happening, there's a tool that can reason about it quicker. 2. Code reviews and security reviews happen quicker and produce more findings. I would think that (m)any team(s) using AI might also be seeing a higher rate of finding and fixing issues. Even the Linux Kernel (I'd say Windows and Apple too) are seeing the same phenomenon.
- Supermancho 2mo agoLinus: "it keeps finding embarrassing bugs" Linux Kernel: https://lore.kernel.org/all/CAHk-=wi4zC+Ze8e+p3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/ https://lore.kernel.org/all/CAHk-=wi4zC+Ze8e+p3tMv8TtG_80Kzs... The idea that software has gotten so complex that a machine can evaluate code paths better than a human, seems to bristle the fur of many. Some people didn't think we would see the day where that comparative human limitation was laid bare in simpler tasks than they expected. I believe older developers are less likely to be offended, having to deal with this as a matter of course (as the mind declines).
- beepbooptheory 2mo agoI don't know, this more and more feels like a sentiment projected on to people than anything real these days.. Like even in that linked thread, is personal offense like you lay out here really were you can place Laurent Pinchart's push back? You don't read anything else there at all? And either way, what, we are going to keep this line going for another 5 years? Aren't you bored?
- Supermancho 2mo ago> You don't read anything else there at all? The citation was in support of the post above mine and was incidentally a link to a mailing list. I did not read the mailing list threads out of personal interest, admittedly. I think it's a particularly bad way to communicate (took 15 years for me to figure it out), so I avoid them. > Like even in that linked thread, is personal offense like you lay out here Taking it personally, is a concrete demonstration of what I described. The replies to my comment, are unsurprising.
- beepbooptheory 2mo agoOh huh well OK. thanks anyway?
- skydhash 2mo ago> The idea that software has gotten so complex that a machine can evaluate code paths better than a human, seems to bristle the fur of many Lol! What about fuzzers, linters, typecheckers and formal tooling? There’s plenty of machine code evaluators that people do use because it’s better than relying on human skills. The issue is the actual report and the lack of information.
- levkk 2mo agoThere is a difference between using an electric drill and having a robot assemble the entire car.
- QuercusMax 2mo ago
- NitpickLawyer 2mo agoGoogle's entire modus operandi has been "automate everything" for decades. They've been doing this with fuzzers, with project zero and so on. Adding LLMs on top is a very obvious next step. And LLMs improving and finding more bugs also follows. Then improve the harness and the dev tools, to better use the LLMs. And then everything together end-to-end to find-triage-fix-confirm. Your LLMs are as good as the loop they run in, and the loop is as good as the verifier. Seems a reasonable enough dynamic without (or despite, depends how cynical you wanna be) the need for managers to show number goes up on some chart.
- jayd16 2mo agoSo thinking about this, do you think these bugs are all unique or are there a small set of new bug categories that were found and once automated resulted in many separate bug fixes? For many of the new bugs, do we think they would all have been prioritized in the past? Are these all critical bugs that would have all been addressed in a timely fashion or are they getting done because its easier to do. Another way to ask it would be, do we think we're discovering that Chrome had more big holes than we thought or are we raising the security bar by fixing smaller holes?
- gbalduzzi 2mo ago> do we think we're discovering that Chrome had more big holes than we thought or are we raising the security bar by fixing smaller holes? To me the most probable explanation is that they automated a way to find (and fix) existing vulnerabilities in a way that was not possible before. Some holes were probably very small, some were probably almost impossible to actually exploit, I don't doubt it. But still, I find it very hard to not consider this a strong security improvement overall (unless they made those numbers up)
- deleted 2mo ago[deleted]
- flohofwoe 2mo agoI would guess they have been confronted with an initial flood of newly discovered bugs whenever they added a new analysis tool or approach (e.g. automated static analysis, fuzzing, ...). Once working through that initial flurry of newly discovered bugs one would assume that the frequency goes down again.
- feelamee 2mo ago> In early 2026, we saw a gradual increase in all categories of bug reports, but by March, the shift was apparent: we received more bug reports than we had in the entirety of 2025 sure, moreover - maybe big AI usage significantly influenced the amount of bugs. So, the picture can be like that: - 2025: 50bugs found, 45fixed - 2026: 500bugs found, 450 fixed
- runarberg 2mo agoThis is just my hypothesis, but I suspect that at Chrome‘s engineering team there has been a culture of inaction for the past decade or more. That nothing gets done, no bugs fixed, unless some higher ups at Google sees a business interest in resolving it. And what has changed now is that the higher ups at Google do indeed see a business interest in fixing bugs and giving the credit to AI to sell us more AI.
- dawnerd 2mo agoThink that’s the case at a few big companies. No doubt Microsoft trying to clean Windows up will give credit to their new ai models.
- coliveira 2mo agoBingo. The issue is not lack of knowledge but prioritization at these companies. Microsoft has the ability to fix Windows bugs, they just think it's secondary compared to adding their own new bug ridden features.
- fhn 2mo agoHard disagree. Google holds browser PWN contests and pay people for reporting bugs. If they can find the bugs themselves, they won't have to pay others. Also, there is a business interest, controlling the browser market helps their data collection and ad business. People could drop Chrome like they drop IE if Chrome does not perform - there are other browsers. "inaction for the past decade or more." I don't follow Chrome dev but this is entirely false.
- rustfreeforme 2mo ago[dead]
- crudgen 2mo agoNah they just write blog posts when they feel like it /s
- mccr8 2mo agoAI is very good at finding security bugs. If you are working on a product that processes hostile data like a web browser and has a security bug bounty program, your choices are either to find them yourself or be overwhelmed by external submissions.
- MollyRealized 2mo agoI will say - and this is just my own experience and not a certain userwide trend response - that one benefit of LLMs is that they are able to take an annoyed observation and format it into a pretty stellar bug report, and then the human being can work on spit-polishing. Having the middle part of the composition automated is a real benefit (at least IMO) - I've been a better reporter. I previously reported on my own and was ignored; now, not so much. I assume that the assistance by the LLM is providing needed detail or formatting. (Yes, I am reading what I am submitting and making sure it is optimal before sending it.)