Google has shifted its Chrome browser to a two-week update cycle, cutting in half the previous four-week release schedule, in a direct response to AI-enabled attackers who can now discover and weaponize software vulnerabilities within hours or days. The change, announced last week for both desktop and mobile versions, aims to shrink what's known as the "patch gap"—the dangerous window between when a security fix appears in Chrome's public code and when it reaches users' browsers. According to Google's Ben Mason, lead of Chrome browser release, and distinguished engineer Deepak Ravichandran, the company is racing to keep pace with threat actors who harness AI to exploit weaknesses that once took weeks or months of human effort to find.
The accelerated schedule targets what Google calls the "N-day" problem—the reality that any number of days can pass between a vulnerability's public disclosure and the moment every user's system is actually protected. By moving from a four-week to a two-week cycle, Google is aiming to cut the maximum window from 28 days down to 14. But the company isn't stopping there. Mason revealed that Google is already piloting twice-weekly security releases, which would deliver patches to browsers multiple times each week rather than once every two weeks. For enterprise customers who use Chrome's Extended Stable channel—which updates major features only every eight weeks—critical security fixes will continue to arrive on the regular weekly schedule, meaning businesses don't sacrifice protection for the sake of stability testing.
Mason told ZDNET that once a security patch is committed to the public Chromium open-source repository, it becomes visible to everyone, and delaying delivery only extends the period during which users remain exposed to attacks. He characterized the shift as essential in an era where "large language models are enabling automated, faster vulnerability discovery and exploit generation." The report notes that AI-powered tools now allow attackers to run comparisons on software versions, identify what was fixed, and then target systems that haven't yet applied the update—a process that can unfold in minutes. According to Picus Security associate security research engineer Umut Bayram, organizations can't afford to respond to an attack that unfolds in minutes with defense processes that take days.
The faster patch cycle addresses one side of the equation, but Google acknowledges a problem beyond its control: users who delay or ignore updates. The company is developing dynamic patching capabilities that would apply security fixes without requiring a full browser restart, though Mason said this work is still in early stages. In the meantime, Google is leveraging opportune restart windows—such as macOS background restarts when all browser windows are closed—and improving session restore features to make updates less disruptive. The report emphasizes that in an environment where AI can both discover vulnerabilities and craft highly personalized spearphishing attacks at scale, the traditional trade-off between security and patch fatigue no longer holds. Mason framed the calculus bluntly for enterprises weighing application stability against cyber risk: weekly security backports to Extended Stable ensure that companies can maintain rigorous vetting processes for major feature updates while still receiving immediate protection against the most serious threats, because "any unpatched vulnerability can be analyzed and targeted much faster" in the AI era. The challenge now is whether browser makers can eliminate the human delay in applying patches before threat actors eliminate the human delay in exploiting them. For organizations accustomed to months-long deployment cycles, that compression demands a fundamental rethinking of how quickly infrastructure can safely absorb change—a shift that will test not just technology but institutional reflexes built for a slower threat landscape.

