Google Accelerates Chrome Updates to Outrun AI Hackers

Google

Google has begun releasing updates to its Chrome browser every two weeks rather than the previous four weeks, the company said in a Tuesday (Sept. 8) blog post.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The new schedule began with the Tuesday launch of Chrome 153 on Desktop, Android and iOS, and it will continue with the planned Sept. 22 Stable release of Chrome 154, according to the post.

    The new two-week release cycle builds on the predictable release cadence Google began in 2010 and the four-week release cycle the company began in 2021, per the post.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    “By shifting to a two-week release cycle today, we are once again raising the bar for browser delivery and security, setting a standard that many across the web ecosystem are also adopting (Microsoft, Mozilla, Brave),” Google Senior Technical Program Manager Ben Mason and Distinguished Engineer and Senior Director Deepak Ravichandran said in the post.

    More frequent deployment of browser updates benefits developers by making deployment windows tighter, interoperability updates quicker to arrive and safety improvements faster to reach users. For users, the two-week release cycle offers more frequent feature updates and quicker security fixes, according to the post.

    “With automated AI discovery tools and community bug reports generating higher patch volume, shorter release cycles make managing security fixes significantly simpler,” Mason and Ravichandran said in the post. “Shrinking the window between landing a fix in the public codebase and delivering it to end users keeps the ‘N-day’ patch gap as small as possible, helping us protect against fast-moving threats.”

    N-day attacks are those in which attackers reverse engineer bugs when the fix for those bugs becomes visible in the public open-source codebase, so that they can exploit those bugs before the fix reaches users’ machines, Google said in a July 30 blog post.

    Google announced in a March 3 blog post that Chrome would shift to a two-week release cycle on Sept. 8. The company said at the time that updates that are more frequent but with a smaller scope would minimize disruption and simplify post-release debugging.

    In its July 30 blog post, Google said that in addition to the two-week cadence, the company was piloting a shift to two security releases per week due to the need to stay ahead of attackers.

    Apple said in June that it accelerated its release of security updates in response to the speed with which artificial intelligence can develop malicious hacking tools.