Google is using AI to improve security in its Chrome browser codebase. Recently, the California-based giant announced its new AI vulnerability agent, created with its Gemini security LLM model. It detected a long-lived sandbox escape bug that could trick Chrome into reading local files. The bug went unnoticed for over 13 years, says Google.
Google also announced tweaks to the security LLM model to ensure security integrity. They are adding restrictions to set boundaries for the AI agent when detecting vulnerabilities.
Moving forward, Google is scaling up AI to automate bug validation, triaging, and fixing, tasks that usually rely on human expertise. Here is everything we know so far:
Since the AI boom, Google has been building a dedicated trusted AI agent to streamline operations.
Google has worked on LLM models for years and in 2023 used them to improve overall performance. Adding AI to core security is a crucial initiative for a company like Google.
To make this a success, Google spent years collaborating and building multiple projects to build an AI agent from scratch.
Google collaborated with Naptime on Project Zero and developed an AI vulnerability agent with research capabilities.
The following year, in collaboration with DeepMind, Project Zero and a new project called Big Sleep helped build an AI vulnerability agent that can research, find, and fix bugs within Google’s core codebase.
Surprisingly, the AI vulnerability agent turned out to be way more efficient and was able to find a major Sandbox escape bug that could potentially allow users to access local files by tracking the browser.
Source link







