Skip to content
Some links are advertising or affiliate links. How we make money
THRYV News

Independent reviews, guides and reporting.

Software & CRM

News

Google's AI Agent Found a 13-Year-Old Critical Flaw Buried in Chrome's Code

The vulnerability, already patched, could have let a compromised webpage trick the browser into reading local files — part of a record year for AI-assisted bug hunting at Google.

By THRYV Money Desk·Published August 18, 2026·Updated August 18, 2026·3 min read
Google's AI Agent Found a 13-Year-Old Critical Flaw Buried in Chrome's Code
Software & CRM · Illustration commissioned for THRYV. Photography is replaced with original imagery as each story is produced.

The takeaway

Google says an AI agent built on its Gemini models found a critical, 13-year-old Chrome vulnerability, CVE-2026-3545, that could let a compromised renderer read local files, rated 9.8 out of 10 in severity. Chrome has patched over 1,800 security bugs in 2026, including 1,072 across two recent releases, with no evidence the flaw was exploited before patching.

Google says an AI agent built on its Gemini models uncovered a critical, 13-year-old security flaw hidden in Chrome's code — a vulnerability that had gone undetected through more than a decade of the browser's development.

What the flaw did

The vulnerability, tracked as CVE-2026-3545, involved insufficient data validation in Chrome's navigation handling. It could have allowed a compromised renderer process to trick the browser into reading local files, effectively enabling a sandbox escape. The flaw received a CVSS severity score of 9.8 out of 10, among the highest possible ratings. Google patched it in Chrome 145 in early May, and the company says it has seen no evidence the flaw was ever exploited in the wild.

A record year for bug hunting

The discovery is part of what Google describes as a record pace of AI-assisted vulnerability patching in Chrome this year.

  • More than 1,800 total security bugs patched in Chrome during 2026
  • Chrome 149 and 150 releases together patched 1,072 defects, more than the prior 23 milestones combined
  • Chrome 151 alone contained 370 security fixes
We've built all of this with safety in mind, and have put in place guardrails to mitigate the risk of AI behaving unexpectedly.
Google

Should you worry?

No action is required beyond keeping Chrome updated. The flaw was already patched months before Google's disclosure, and the company reports no evidence it was exploited. Chrome updates automatically for most users, but anyone unsure can check their version manually and restart the browser to apply pending updates.

Sources

This article is original writing by THRYV. We link to primary reporting and official documents rather than reproducing them.

  1. Google's AI Agent Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceSecurityWeek

Why you can trust this article

Written and edited in-house by the THRYV Money Desk. We do not republish or reword agency copy, and we do not invent quotes, statistics, testimonials or ratings. Where figures move frequently, we point you to the primary release rather than printing a number that will be out of date. Advertising and affiliate partnerships have no influence on our reporting — see our editorial standards, fact-checking policy and affiliate disclosure. Spotted an error? Write to newsroom@thryv-news.com.

General information only. Not personalised financial, medical or legal advice.

Related reading

The THRYV Brief

The market in 5 minutes, weekday mornings

Plain-English analysis, the sources behind it, and what it changes for you. Free, and you can unsubscribe any time.

Free. Unsubscribe any time. We never sell your email address.

Advertisement · Newsletter sponsorship600×120
Advertise with THRYV News — medium rectangle placement available

This position is available to a single sponsor per edition, is labelled in the email and on this page, and does not influence what the Brief covers.

Advertisement
Advertise with THRYV News — medium rectangle placement available