Google says an AI agent built on its Gemini models uncovered a critical, 13-year-old security flaw hidden in Chrome's code — a vulnerability that had gone undetected through more than a decade of the browser's development.
What the flaw did
The vulnerability, tracked as CVE-2026-3545, involved insufficient data validation in Chrome's navigation handling. It could have allowed a compromised renderer process to trick the browser into reading local files, effectively enabling a sandbox escape. The flaw received a CVSS severity score of 9.8 out of 10, among the highest possible ratings. Google patched it in Chrome 145 in early May, and the company says it has seen no evidence the flaw was ever exploited in the wild.
A record year for bug hunting
The discovery is part of what Google describes as a record pace of AI-assisted vulnerability patching in Chrome this year.




