
Google's AI vulnerability agent, powered by the Gemini security LLM, identified a critical sandbox escape bug in Chrome that had remained undetected for over 13 years.
The bug could have allowed unauthorized access to local files, but Google's security team successfully patched the vulnerability before any exploitation occurred.
Google is now implementing five security pillars, including a dedicated knowledge base and critic agents, to restrict AI agent access and automate future bug validation.