模型与实验室 4.0 · 优秀 2026-07-30 · 文章

Chrome 用 Gemini AI 加速漏洞发现分类和修复(Google)

Google Chrome 安全团队详细介绍了如何用 Gemini LLM 自动化漏洞发现分类和修复2026年初构建的 Agent harness 发现了一个存在 13 年的沙箱逃离漏洞改进包括:模型互操作性Chrome CVE 知识库SECURITY.md 文件辅助威胁建模独立上下文的 critic agent多轮运行应对模型不确定性所有 AI 分析在无互联网的锁定环境中运行,严格限制子 Agent 的文件访问范围2026年6月修复的 Chrome bug 数量超过过去两年总和

打开原文回到归档

Chrome 用 Gemini AI 加速漏洞发现分类和修复(Google)

Source: <https://blog.google/security/chrome-stronger-with-every-update&gt; | 2026-07-30
Author: Chrome Security Team | Category: agents | Quality Score: 4/5
Tags: ai-security, gemini, vulnerability-detection, chrome, fuzzing

English Summary

Google's Chrome Security Team details how Gemini LLMs automate vulnerability discovery, triage, and patching. An early-2026 agent harness found a 13-year-old sandbox-escape bug (crbug.com/487383169). Improvements include model interoperability, a Chrome CVE knowledge base, SECURITY.md-assisted threat modeling, a separate-context critic agent, and multi-run scanning for model non-determinism. All AI analysis runs on locked-down machines without internet; subagents are strictly sandboxed. Chrome fixed more bugs in June 2026 than over the past two years combined, thanks to AI.

中文概要

Google Chrome 安全团队详细介绍了如何用 Gemini LLM 自动化漏洞发现分类和修复2026年初构建的 Agent harness 发现了一个存在 13 年的沙箱逃离漏洞改进包括:模型互操作性Chrome CVE 知识库SECURITY.md 文件辅助威胁建模独立上下文的 critic agent多轮运行应对模型不确定性所有 AI 分析在无互联网的锁定环境中运行,严格限制子 Agent 的文件访问范围2026年6月修复的 Chrome bug 数量超过过去两年总和