Google、AI エージェントで Chrome のセキュリティバグ 1,072 件を 60 日間で発見・修正
本文の状態
日本語全文を表示中
詳細モードで約14分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
ZDNET AI
Google は AI エージェントを活用して 60 日間で Chrome のセキュリティバグ 1,072 件を発見・修正し、その成果として数十年にわたる欠陥の発見や開発工時の大幅短縮を実現した。
AI深層分析を開く2026年8月4日 16:01
AI深層分析
キーポイント
AI エージェントによる大規模バグ検出と修正
Google は AI エージェントを Chrome プロジェクトに投入し、60 日間で 1,072 件のセキュリティバグを発見して修正した。
人間が見過ごした長期欠陥の発見
AI の分析により、人間が繰り返し見逃していた 10 年前から存在する Chrome の欠陥が発見された。
開発工時の劇的な短縮効果
Google は AI ワークフローの導入により、従来の手法に比べて数週間分の開発時間を節約できたと発表した。
AI導入によるバグ発見数の急増
AIの活用により、M149とM150で計1,072件のセキュリティバグが修正され、これは過去23マイルストンの合計数を上回る規模となった。
Chromeのセキュリティ責任の重大性
地球人口の半数以上がChromeを利用しているため、単一の脆弱性が流出すれば世界中の成人に即座にリスクが及ぶ。
重要な引用
AI found a decade-old Chrome flaw humans repeatedly missed.
Chrome and its open-source project, Chromium, are, by scale, among the most complex open-source projects on the planet.
"surpassing the total number of security bugs fixed across the prior 23 milestones combined."
Just letting one security flaw loose into the wild immediately puts half the adult humans currently alive at risk.
編集コメントを表示
編集コメント
Chrome のような巨大なコードベースにおいて、AI エージェントが人間よりも効率的に欠陥を発見・修正できる事例は極めて貴重である。この成果は、ソフトウェア開発のセキュリティ確保における AI の役割を再定義する重要な転換点となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET の注目ポイント
- AI が、人間が何度も見逃した 10 年前の Chrome の欠陥を発見。
- Google は、この AI ワークフローにより開発者の時間を数週間節約できると説明。
- 数十億人のユーザーを守るため、Chrome は週に 2 回のパッチ適用が必要になる可能性も。
Chrome とそのオープンソースプロジェクトである Chromium は、規模の点で地球上でも最も複雑なオープンソースプロジェクトの一つです。世界のブラウザ市場シェアの約 73% を占める Chrome には、現在およそ 35 億人のアクティブユーザーがいます。この数字を比較すると、35 億人はアメリカ合衆国の人口(大人と子供を含む)の 10 倍以上に相当します。
成人人口全体に関する信頼できる参照資料が見つからなかったため、私は計算を行いました。世界の総人口や地球上の児童数のデータに基づくと、地球には約 60 億人の成人がいます。この数字から、Chrome は地球上の成人の過半数がインターネットにアクセスする主要な手段であることがわかります。
関連記事: Claude AI の共有チャットが Google でインデックス化 - あなたの会話も漏洩していないか確認
つまり、Chrome の開発者にとって責任の重さは計り知れません。セキュリティ上の欠陥が一つでも外部に流出すれば、現在生存している成人人口の半数が即座に危険にさらされることになります。
Google はこの責任を非常に真剣に受け止めています。先週、Chrome セキュリティチームは、AI を活用して「脆弱性の発見、選別、パッチ適用」を強化する取り組みについて詳細を記したブログ記事を発表しました。
関連記事: この強力な Gemini の設定により、私の AI 結果がよりパーソナライズされ、精度が高まりました
その規模、課題、AI がどのように役立っているか、そして逆に AI が膨大な数の新たな脆弱性を露呈させているという事実は、非常に興味深い物語を生み出しています。このテーマは解明する価値があります。
1 つのチャートにまとめた全体像
Google は毎月のリリースを「マイルストーン」と呼んでいます。下のチャートは、2024 年 8 月 20 日に公開された Milestone 128 から始まります。M145 までの各マイルストーンで Google は約 50 のバグを修正しました。しかし M146 では約 80 に、M147 では約 130 に増加。そして M148 では一気に約 350 件に達しています。
*チャートはホッケースティック型の成長曲線を示しています。画像:Google*
月を追うごとに発見・修正されたバグの数は倍増しました。M149 と M150 では、過去 23 マイルストーンの合計を上回る 1,072 のセキュリティバグが修正されました。
その背景にある意味合い
この規模の対応は、その logistics(運用体制)を考えると驚異的です。Google は毎月大規模な新リリースを実施しているため、世界中で混乱を引き起こすリスクは常に高い状態にあります。もしバグを修正する代わりに、重大なバグがデプロイ後に発見される前にリリースされてしまったら、地球上の成人の半数にとって最悪の日になってしまうかもしれません。
M128 の時点で処理された 40〜50 件のバグそれぞれについて、Google は以下の手順を踏まなければなりませんでした。バグの検証、修正の実施、そして数億ものウェブページや数十万の Chrome 拡張機能との競合がないか QA(品質保証)を行い、修正版のリリース、さらにユーザーへのブラウザ更新の呼びかけです。
また、Google Earth に「Nano Banana」が追加され、私はすぐにゾンビや悪の道化師がいるフィラデルフィアを再想像しました。
これは、Google 社のような大企業が開発チームを投入していても、約 1 ヶ月で達成するには相当な量です。
もちろん、Google は以前から AI ツールを使ってこれらのリリース管理を行ってきました。2023 年には、AI を活用してセキュリティのファジングカバレッジ(主に予期せぬランダムな入力によるテスト)を拡大しました。そして 2024 年、M128 の時期頃には、脆弱性分析を行うための専門的な AI ツールの導入も始めました。2025 年には、「DeepMind と Project Zero と協力し、V8 JavaScript エンジンやグラフィックススタックでバグを発見した AI 脆弱性発見エージェント『Big Sleep』を共同開発しました」と発表しています。
そして 2026 年、Google は Gemini を基盤としたエージェントハネス(LLM と対話するための構造)を導入し、Chrome のコードベース全体にわたる脆弱性の発見能力をさらに強化しました。
これは直線的なプロセスではありません。単にコードを見て入力値のサニタイズが不十分だと気づくだけの話でもありません。むしろ、AI が数千手先の手を予測するチェスのようなものです。コードを見るだけでなく、シナリオをシミュレーションします。数十億ものシナリオです。
これを行っても必ずしもコード上の欠陥が見つかるわけではありません。コード自体は堅牢な場合もあります。重要なのは、セキュリティ障害を引き起こす可能性のある相互作用のパターンとして現れる脆弱性を見つけることです。
具体例として、2013 年から Chrome に存在していた「サンドボックスエスケープ」と呼ばれる脆弱性が挙げられます。これは悪用されるとブラウザがローカルファイルを読み出してしまうバグです。この欠陥は Chrome のコードに埋め込まれたまま、テストスイートを何回も通過し続け、*10 年以上もの間*放置されていました。Gemini は 2026 年初頭にこれを発見しました。
関連記事: AI での会話を可能な限り非公開にする方法
しかし、ここで重要なのは、1 ヶ月に 40〜50 の脆弱性であれば Google 規模のチームにとって管理可能ですが、2 つのリリース期間で 1,072 ものバグが見つかったのはもはや圧倒的な事態だということです。
この2つの示唆は非常に重要です。まず、AI がこれほど多くの脆弱性を発見できるなら、その能力を管理や修復、テスト、修正プログラムの展開にも活用できる可能性があります。第二に、Google の AI がこれだけの脆弱性を見つけられるなら、敵対的なアクターが運用する AI も同じことができるということです。では、Google が見つけて修正した脆弱性と、悪意のあるグループが発見して悪用する脆弱性が一致しているとはどうやって言えるのでしょうか?
これは非常に不安な状況です。
爆発的な軍拡競争
重要なのは、対応の速度が光速並みでなければならないということです。何十億もの人々がこのシステムに依存しています。しかし、彼らが求めているのは単なる修正プログラムの継続的な供給だけではありません。それらの修正によって事態が悪化しないことを確信したいのです。
これを管理するために、Google は4段階のトリアージ体制を構築しました。
第1段階では、AI エージェントが誤った報告や重複した報告、そして Chrome のセキュリティ脆弱性を実際に記述していないバグレポートを選別します。Google はこれを「ノイズの除去」と呼んでいます。まるでメールボックスからスパムを整理する作業のようなものです。
第2段階では、AI エージェントが実際にバグの再現を試みます。バグ報告で特定されたブラウザとオペレーティングシステムに対応した仮想環境で Chrome を実行し、動作を確認します。もしバグが再現できれば、AI はスタックトレースなどの追加情報をレポートに付加します。
関連記事: オープンウェイト型とクローズド型の対立:AI 界の市民戦争勃発、その行方は人類の存亡に関わる
バグレポートを人間が確認する段階は、非常に時間がかかる作業です。私の小さなプロダクトでバグ報告を受けると、ユーザーが報告した内容が実際に正しいかどうかを確認するために数時間を費やすことがあります。これは修正にかかる時間ではなく、そのバグを「やるべきリスト」に残すべきか判断するための時間です。もし Google が Gemini にこの作業を自動化させられれば、コーディングチームの時間節約は計り知れません。
第 3 ステージでは、AI エージェントが「レポートにメタデータを追加します」。私たちはみな、探偵ドラマで探偵が事件の警察報告書やファイルを受け取る場面を見たことがあるでしょう。そのファイルには、担当捜査官に引き継ぐ前に、事件に関するすべての背景情報が含まれています。第 3 ステージはまさにそれを行っています。AI エージェントは、引き継ぎに備えてレポートを構築しているのです。
そして第 4 ステージでは、AI エージェントが適切な人間担当者(オーナー)を特定し、事件情報をその捜査官へ引き渡します。これにより、捜査官は調査に集中でき、事件を開始するために必要な事務手続きに時間を費やす必要がなくなります。
関連記事: Chrome の AI エージェントに買い物、リサーチ、メールの代行をさせた - その結果
Google は「正確な測定は難しいものの、この新しいプロセスにより、開発者の時間を毎月数百時間節約できていると推定している」と述べています。
機械同士が戦う。これがエクスプロイトの速度が急加速する現状に対処するための唯一の方法だ。ただし、最も避けたいのは、AI が誤った修正を生成し、世界中の成人の半数に配布された後に機能しなくなることである。
それでも、数千もの脆弱性が次々と発見されるスピードに対応するため、Google はバグ修正プロセスのスケーリングが必要だった。そこでブログ記事で説明されているのが、マルチエージェント・ワークフローだ。
関連記事: Google Search で無料で AI 画像を即座に生成する方法
コードを書いて修正案を多数生成する「修正エージェント」がいる。そして「批評家エージェント」がその修正を検証し、問題に対して最も適したものを特定するとともに、開発者が評価できるよう追加の情報を提供する。
この 2 つのエージェントは、コードが機能し、スタイルガイドラインに準拠していることを確信できるまで、従来のコードレビュープロセスと同様に循環して作業を繰り返す。
次に登場するのが、テスト作成を担当する多数のエージェントたちだ。これらのエージェントはテストを構築し、Chrome のすべてのサポート対象プラットフォーム上で Chrome をテスト実行する。これにより、人間が開発者として修正を検証する前に、問題を見つけ、修正担当の「修正エージェント」と「批評家エージェント」にフィードバックできる。
Google によると、このプロセスによって開発者の時間を数週間節約できているという。
しかし、ユーザーは頑固だ
攻撃者が脆弱性を発見して悪用するのと、修正プログラムが公開されるまでの間には時間差があります。たとえ Google が「実際に悪用されているバグ」を把握していたとしても、通常、Chrome の安定版に修正が反映されるまでには数週間かかっていました。
Google は現在、主要な機能更新は 2 週間に一度、セキュリティ関連のアップデートは毎週リリースする体制へ移行しようとしています。しかし、攻撃のスピードが増している現状を踏まえ、今後は週に 2 回のセキュリティリリースを行う方向で進めています。
実はここ約 10 年間、Chrome はバックグラウンドで静かに更新ファイルをダウンロードし、ディスク上に準備を整えておく仕組みを採用してきました。そして、ユーザーが Chrome を再起動した際に自動的に適用されるという方式です。
関連記事: AI オーバービューに飽きた?リンクを表示する Google サーチの代替手段 9 選
もちろん、誰も週に 2 回も Chrome のアップデートをインストールしたくありませんし、再起動も面倒です。しかし、これが問題なのです。なぜなら、修正プログラムがダウンロードされてからユーザーが実際に Chrome を再起動するまでの間に、十分な時間が空いてしまうからです。その隙に攻撃者が悪用してしまうリスクがあるのです。
Google は、ユーザーに負担をかけずにアップデートを適用する方法の開発を進めています。具体的には、ブラウザの再起動を不要にする動的パッチング機構の実験や、ローカルでブラウザの状態を保存してすぐに再開できるようにする取り組みが行われています。また、ユーザーにとって邪魔にならない適切なタイミングを見つけてブラウザを再起動させるという戦略も検討されています。
関連記事: Chrome vs. Edge vs. Firefox: I tested each browser's AI, but I'm only sticking with one
ユーザーとして、ベンダーが勝手に私を管理してアップデートを強制するのは好ましくありません。しかし、悪意のある攻撃者が私のマシンを乗っ取ろうとするのも同様です。Google はこの微妙なバランスの取り方を模索しており、その試みは成功する可能性があります。
ブラウザを守り、世界を守る
Google は、防御ワークフローに AI をどう統合しているかについて多くの技術情報を公開しています。技術的な詳細も興味深いものですが、それ以上に重要なのは戦略的な意味合いでしょう。
関連記事: Google is training AI on even more of your data now, unless you opt out - here's how
AI の登場により、攻撃のペースは加速しました。しかし、防御側のペースも同様に加速しています。この軍拡競争はこれまで以上に熾烈を極めています。もし Google が 2 年分のバグを 2 ヶ月で見つけ出すことができるなら、その比率からイノベーションのスピードが推し量れるはずです。
コードの進化はかつてないほど加速しています。AI によるコーディング、攻撃、防御が 1 年間に及ぶ活動で得られる成果は、従来なら 12 年かかったものをわずか 2 ヶ月で達成するレベルです。つまり、毎年 10 年以上にわたる技術進歩を成し遂げていることになります。
そのスピードは圧倒的です。この加速の要因は AI にあり、私たちは今や、AI の力を借りて同等の速度で防御を行う必要があります。
*日々のプロジェクトの更新情報はソーシャルメディアでフォローできます。週刊ニュースレターへの購読と、Twitter/X(@DavidGewirtz)、Facebook(Facebook.com/DavidGewirtz)、Instagram(Instagram.com/DavidGewirtz)、Bluesky(@DavidGewirtz.com)、YouTube(YouTube.com/DavidGewirtzTV)でのフォローをお忘れなく。*
原文を表示

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET's key takeaways
- AI found a decade-old Chrome flaw humans repeatedly missed.
- Google said its AI workflow saves weeks of developer time.
- Chrome may need twice-weekly patches to keep billions safe.
Chrome and its open-source project, Chromium, are, by scale, among the most complex open-source projects on the planet. With some 73% of the global browser market share, there are about 3.5 billion active Chrome users. To put that in perspective, 3.5 billion is more than 10 times the entire population (adults and children) of the United States.
I couldn't find a good reference for the overall adult population, so I used math. Based on data for the overall population of the world and the number of children on the planet, there are a little under 6 billion adults on Earth. The math shows us that Chrome is the primary way more than half of us earthlings access the internet.
Also: Claude AI shared chats indexed by Google - see if your conversations were exposed
The stakes, therefore, are incredibly high for Chrome's developers. Just letting one security flaw loose into the wild immediately puts half the adult humans currently alive at risk.
Google clearly takes this responsibility quite seriously. Last week, the Chrome security team released a blog post detailing how it is using AI to "improve vulnerability discovery, triage, and patching."
Also: This powerful Gemini setting made my AI results way more personal and accurate
The scope, the challenge, how AI is helping, and how AI is also exposing overwhelming numbers of new vulnerabilities make for quite the story, one worthy of deconstruction.
The whole story in one chart
Google called its releases "milestones," which occur about once a month. The chart below begins with Milestone 128, which dropped on Aug. 20, 2024. For each milestone up to M145, Google fixed roughly 50 bugs. Then M146 jumped to about 80 bugs. M147 fixed about 130 bugs. M148 fixed about 350 bugs.
*The chart shows a hockey-stick growth curve. Image: Google*
Month by month, the number of bugs found and fixed doubled. Then, for M149 and M150, Google fixed 1,072 bugs, "surpassing the total number of security bugs fixed across the prior 23 milestones combined."
There are ... implications
The logistics of this are mind-blowing. With Google issuing major new releases on a monthly basis, the potential for causing disruption worldwide is fairly high. If, instead of fixing a bug, Google were to introduce a serious bug that made it past deployment before discovery, it could ruin the day for half of all living adult humans.
For each of the 40 or 50 bugs dealt with back in M128, Google had to validate the bug, fix the bug, QA the fix to make sure it didn't conflict with the billions of web pages and hundreds of thousands of Chrome extensions, release a fix, and then encourage users to update their browsers.
Also: Google Earth added Nano Banana, and I immediately reimagined Philly with zombies and evil clowns
That's a lot to accomplish in roughly a month, even with a developer army that a company like Google can task with the work.
To be sure, Google has been using AI tools to manage these earlier releases. Back in 2023, Google used AIs to increase security fuzzing coverage (basically testing with lots of unexpected, random inputs). By 2024, about the time of M128, Google started to add specialized AI tools to do vulnerability analysis. In 2025, the company said, "We collaborated with DeepMind and Project Zero on Big Sleep, an AI vulnerability discovery agent that successfully found bugs in the V8 JavaScript engine and graphics stack."
Then, in 2026, Google upped its game with an agentic harness (a structure for interacting with LLMs) based on Gemini that was designed to find vulnerabilities across the entire Chrome codebase.
This is not a linear process. It's not just a matter of looking at code and realizing that inputs weren't properly sanitized. Instead, it's much more like a game of chess, except the AI is predicting moves thousands of moves ahead. It's not just looking at the code. It's gaming out scenarios. Billions of scenarios.
Doing this doesn't necessarily find flaws in the code. The code could be rock-solid. Instead, it's finding vulnerabilities, which reflect patterns of interactions that could cause a security failure.
One example of this is a vulnerability called a sandbox escape that has existed in Chrome since 2013. This is a bug that, if exploited, would trick the browser into reading local files. That flaw lived in the Chrome code, passing test suite after test suite, *for more than a decade*. Gemini found it in early 2026.
Also: How to keep your AI conversations as private as possible
But here's the thing. While 40 or 50 vulnerabilities in a month are moderately manageable for a Google-sized team, 1,072 bugs over two releases are nothing short of overwhelming.
Here are the two main implications. First, if the AI can find that many vulnerabilities, perhaps it can help manage, repair, test, and deploy fixes. Second, if Google's AI can find that many vulnerabilities, so can AIs operated by enemy actors. And who's to say that the vulnerabilities Google finds and fixes are the same ones that the bad guys find and exploit?
It's all very disturbing.
An explosive arms race
The thing is, the rate of reaction has to be at warp speed. Billions of people are depending on it. But all those people aren't just counting on a continual flow of fixes; they're counting on those fixes not making things worse.
To manage this, Google has developed a four-stage triage operation.
At Stage 1, AI agents help filter out the bad reports, duplicate reports, and bug reports that don't really describe a Chrome security vulnerability. Google calls this "filtering out the noise." Think of it like going through your email and clearing out the junk.
At Stage 2, AI agents actually reproduce the bugs. Chrome is put through its paces in virtual environments that correspond to the specific browser and operating system reported in the bug. If the bug can be reproduced, the AI adds additional details, like stack traces, to the report.
Also: Open weights vs. closed: An AI civil war's afoot, and the stakes are existential
This is a time-consuming stage when humans have to do it. When I get a bug report for my small product, it can take me hours to try to confirm that what a user is reporting is actually true. That's not fixing time. That's just time to determine if the bug should stay on my to-do list. If Google can get Gemini to do this automagically, the time savings for the coding team can be considerable.
At Stage 3, AI agents "enrich the report with metadata." How many detective shows have we all seen where the detective is handed a police report or folder on the crime? That folder contains all the background information on the case before it is handed off to an investigator. That's what Stage 3 is doing. The AI agents are building that report in preparation for handoff.
Then, at Stage 4, the AI agents identify the right human owner and hand off all the case information to that investigator. This allows the investigator to focus on the investigation and not spend a bunch of time on the administrative details necessary to initiate the case.
Also: I let Chrome's AI agent shop, research, and email for me - here's how it went
Google said, "While it's hard to measure precisely, we estimate that this new process is saving hundreds of hours of developer time per month."
Machines fighting machines. It's really the only way to handle the rapid acceleration in exploit velocity. But the last thing you want is some AI hallucinating a fix that's delivered to half the adults on the planet and then fails.
But still, with thousands of vulnerabilities being found at speed, Google needed to scale up the bug-fixing process. To do this, the blog post describes a multiagent workflow.
Also: Google Search will let you instantly generate AI images for free - here's how
There's a fixing agent that writes code, producing a bunch of what Google calls candidate fixes. Then there's a critic agent. This AI evaluates the fixes, determines which would be the best fit for the problem, and provides additional supporting information for developers to evaluate the fix.
The two agents, the fixer and critic, cycle in a way similar to a traditional code review process until they can be sure the code is functional and meets style guidelines.
Next up is the small test-writing agent army. These agents construct tests and run Chrome through the tests across all of Chrome's supported platforms. In this way, problems can be found and submitted back to the fixer and critic before any human developer has to review the fix.
Google said this process saves weeks of developer time.
But users are stubborn
There is a gap in time between when attackers find and exploit bugs and when the fixes are released. Even when Google knows there's a bug in the wild, it has typically taken weeks for the fix to reach the Chrome stable channel.
Google is working to transition to a two-week delivery cadence for major milestones and a weekly release for security updates. But with the uptick in attack velocity, Chrome is pushing to do two security releases each week.
For almost a decade, Chrome has used a silent background download mechanism that would stage updates on disk, automatically running updates once a user restarted Chrome.
Also: Tired of AI Overviews? I found 9 Google Search alternatives that showed me links again
And yeah, none of us wants to install two new Chrome releases each week. We also don't want to restart Chrome. But that's a problem because the time between when a bug fix is downloaded and when a user restarts Chrome could be long enough for an exploit to take hold.
Google said it has been working on ways to push updates without being intrusive. It is trying out a mechanism for dynamic patching that may eliminate most browser restarts. It is also working on saving the state of the browser locally so it can be resumed easily. Another tactic is to find opportune and nonintrusive opportunities to restart the browser.
Also: Chrome vs. Edge vs. Firefox: I tested each browser's AI, but I'm only sticking with one
As a user, I really don't like it when a vendor decides to nanny me and force updates. But I also don't like it when bad guys try to exploit my machine. It looks like Google is trying to walk that fine line, and it might just work.
Save the browser, save the world
Google is publishing a lot of technical information about how it is integrating AI into its defensive workflows. While the technical details are interesting, it's the strategic implications that are more profound.
Also: Google is training AI on even more of your data now, unless you opt out - here's how
AI has escalated the pace of attack. It can also escalate the pace of defense. The arms race is hotter and more intense than ever before. If Google can identify and find two years of bugs in two months, we can derive the pace of innovation from that ratio.
Code lives in a faster timeline than ever. Two years in two months means that a year of AI-enabled coding, attack, and defense will produce the output that previously took 12 years. That's more than a decade of advancement every year.
It's overwhelming. AI is causing that speed increase, and because of it, we're now dependent on AI to defend us at speed.
*You can follow my day-to-day project updates on social media. Be sure to subscribe to my weekly update newsletter, and follow me on Twitter/X at @DavidGewirtz, on Facebook at Facebook.com/DavidGewirtz, on Instagram at Instagram.com/DavidGewirtz, on Bluesky at @DavidGewirtz.com, and on YouTube at YouTube.com/DavidGewirtzTV.*
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み