Soft ComputersBook a free IT assessmentBook assessment

Google Fixed 1,072 Chrome Security Bugs in 60 Days: What This Means for Your Business Computers

Managed IT5 min readBy the Soft Computers Team

Google just published details on something that should get the attention of every business owner running computers on Chrome. According to ZDNet, Google deployed AI agents that found and fixed 1,072 security bugs in the Chrome browser in just 60 days. That is not a cumulative annual number. That is two months of automated vulnerability hunting.

We are not writing this to talk about AI research. We are writing this because those 1,072 bugs existed in a browser that is almost certainly installed on your business computers right now. And most Canadian SMBs we work with have no consistent process to make sure Chrome is patched across every machine in their office.

Why the Volume of Chrome Bugs Matters to You

Chrome is the most widely used business browser in Canada. Your staff use it to log into Microsoft 365, your accounting software, your CRM, your bank portal. When a bug exists in Chrome, attackers can sometimes use it to steal session cookies, redirect users to fake login pages, or execute code on the machine without the user doing anything beyond visiting a compromised website.

The traditional security research process found bugs one or two at a time, usually over months. Google's AI agents found over a thousand in sixty days. That pace is not going to slow down. It means the gap between a vulnerability existing and it being actively exploited by criminals is shrinking. The window where you can afford to leave machines unpatched is getting shorter every month.

The Patch Gap Is the Real Risk

Chrome does update automatically on personal computers for most users. But in a business environment, automatic updates get blocked for several common reasons. Group Policy settings on Windows can prevent Chrome from self-updating. Staff who never fully close their browser never trigger the update cycle. Machines that sit unused for days at a time fall behind. Computers running older versions of Windows 10 sometimes have update compatibility issues.

We audit business computers regularly. It is not unusual to find Chrome versions that are four to six weeks behind on a machine that someone uses every day. Four to six weeks used to feel acceptable. Given what Google's research just showed us about the volume of bugs being discovered, that gap is now genuinely dangerous.

What We Recommend for Canadian SMBs

Patching Chrome manually on every machine every week is not realistic for a business owner. Here is what a proper managed IT approach looks like for keeping browsers current.

  • Endpoint management with forced browser updates. Tools like Microsoft Intune, NinjaRMM, or N-able let a managed IT provider push Chrome updates to every machine on a schedule. The update happens whether the user closes their browser or not.
  • Weekly patch compliance reports. Your IT provider should be sending you a report showing which machines are on the current Chrome version and which are behind. If you are not getting this, ask for it.
  • Browser policy enforcement. Beyond version control, IT management tools can prevent staff from installing Chrome extensions that have not been approved. Extensions are a separate and serious attack surface. Google is reportedly working on blocking malicious New Tab hijacker extensions by default, but that is not a substitute for a policy you control.
  • Standardize on one browser where possible. If your team is split between Chrome, Edge, and Firefox, you are managing three separate patch cycles. Consolidating to one browser makes compliance easier to verify and enforce.

This Is Exactly What Managed IT Is For

No business owner should be manually tracking browser patch levels on ten or twenty or fifty machines. That is the kind of operational detail that falls through the cracks when you are running a business, and the consequences of it falling through are real. Ransomware groups actively scan for unpatched browsers as an entry point.

When we take on a new managed IT client, browser patching is one of the first things we audit and lock down. It is not glamorous work, but given that Google's own AI just found more than a thousand bugs in Chrome inside of two months, it is clearly necessary work.

If you are not confident that every computer in your business is running a current, patched version of Chrome, reach out to us. We can run a quick audit and show you exactly where you stand. No pressure, no sales pitch. Just a clear picture of what is on your machines.

Want this level of attention on your IT?

We publish what we practice. Book a free assessment and see where your environment stands: what is solid, what is aging, and what is at risk.