← 返回 Avalaches

Chrome 瀏覽器安全團隊在最新報告中指出,今年六月的兩次主要版本更新共修復了 1,072 個安全漏洞,超過此前 23 次大版本更新的修補總和。這一激增主要源於團隊內部大幅引入 AI 工具進行漏洞發現、分類與補丁開發,Chrome 副總裁 Parisa Tabriz 表示,2025 年是攻防兩端的真正轉折點。

面對 AI 驅動的漏洞發現浪潮,Chrome 正從每兩週一次主要版本發布加每週安全更新,轉向試行每週兩次安全修補的節奏。工程總監 Doug Turner 表示,AI 模型已被訓練掌握 Chrome 歷史上所有已知安全漏洞(CVE)及每一行程式碼的變更原因,使其能精準定位龐大程式碼庫中的潛在弱點,包括已不再積極維護的功能模組。

除了持續修補漏洞外,Chrome 安全團隊同樣致力於結構性安全改進,例如將部分 C++ 程式碼改用記憶體安全的 Rust 語言重寫,以從根本上消除整類常見漏洞。Tabriz 認為短期漏洞激增後將達到新的平衡,但她強調安全改善不會自動發生,業界必須積極將 AI 融入軟體安全開發流程。

Google's Chrome security team reported that the browser's two major June releases included fixes for 1,072 security bugs—more than the combined total of the previous 23 major releases. This dramatic surge has been largely driven by the team's rapidly evolving use of AI tools for vulnerability discovery, triage, and patch development, marking what Chrome VP Parisa Tabriz calls a true inflection point for both offensive and defensive security.

In response to the flood of AI-discovered vulnerabilities, Chrome is piloting twice-weekly security update releases, up from its already accelerated cadence of biweekly major releases with weekly security patches. Director of Engineering Doug Turner explained that AI models have been trained on every known CVE and the complete history of Chromium's codebase, enabling them to pinpoint potential weaknesses across the vast project—including in legacy features that no longer receive active human scrutiny.

Beyond reactive patching, the Chrome security team is pursuing structural improvements such as rewriting portions of C++ code in the memory-safe language Rust to eliminate entire categories of common vulnerabilities. Tabriz anticipates a new equilibrium will emerge after the current spike but cautions that improved security will not come automatically—the entire industry must actively integrate AI into software security development workflows.

2026-08-02 (Sunday) · 592ac154471a869f6e44dfda87506e6ed16f7816