Skip to content

Security1 publisher2 min readPublished

Chrome CVE disclosures rise 563% in a surge VulnCheck partly credits to AI bug hunting

VulnCheck counts Chrome CVEs up 563% and GitHub-issued CVEs up 476% this year, a rise it calls consistent with AI-assisted bug finding. Whether the volume lasts is unknown, so exploitation data still sets patch order.

The Watch · Security desk

Illustration accompanying Chrome CVE disclosures rise 563% in a surge VulnCheck partly credits to AI bug hunting

What happened

  • VMware (+180.9%), Apache (+170.3%), Mozilla (+156.9%), HPE (+132.3%) and F5 (+113.8%) also posted large year-to-date increases in CVE volume.
  • GitHub's team confirmed that both its surge in vulnerability reports and the matching rise in CVE issuance are real.
  • Anthropic announced Project Glasswing and Claude Mythos Preview on April 7, 2026, claiming the model had found thousands of zero-days across every major operating system and browser.
  • VulnCheck's own vulnerability-report intake began the year as a flood of slop and has improved in quality over recent months without falling in volume.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Triage cost for Chrome alone now scales with a CVE count about 6.6 times the prior-year figure, borne by every team that tracks browser fixes.
  • constraint Capacity plans cannot be sized from these figures alone, because VulnCheck published growth percentages without the underlying CVE counts.
  • exposure Open-source maintainers take the first wave: VulnCheck calls open source the testing ground for AI bug finding, and GitHub's reports arrive across many projects at once.

The spread across sources is the strongest part of the record. "No single reporter accounts for more than ~3% of volume, and no single project accounts for more than ~7%. This isn't one person or one tool, it's a systemic shift in how vulnerability reporting is happening across the ecosystem," Madison Oliver Ficorilli said in comments VulnCheck published with GitHub's confirmation [14]. A surge from one prolific researcher or one scanner ends when that source stops. A ceiling of about 3% per reporter puts at least 34 separate reporters behind GitHub's volume [3].

The AI attribution is VulnCheck's inference. The firm calls the signal still emerging and says not every increase can be traced directly to AI [5]. Its case rests on a five-year look at issuance by the top 20 CVE Numbering Authorities [15]. Public accounts from Mozilla, Microsoft, Apache, Curl and Palo Alto show models used to find, validate or triage bugs, with results that varied by project [6].

Anthropic's figure of thousands of zero-days is Anthropic's own claim [10]. The company kept Mythos out of public release and gave access to a partner coalition [11]. VulnCheck began tracking Anthropic-attributed CVEs and published its analysis two Patch Tuesdays after the Glasswing announcement [12].

VulnCheck says it is less clear whether these volumes will be sustained or whether this is a temporary surge as frontier models are applied across different code bases [7]. I think the record supports budgeting for higher intake through this year. Two Patch Tuesdays of post-Glasswing data is too short a window to set a permanent baseline [12].

A disclosure count measures publication. It does not measure exploitation. For a patch program, the total count sizes the triage staff. VulnCheck's guidance is to prepare for the higher volume while using threat intelligence to rank the bugs that are being exploited or are likely to be [8].

What to watch

  • The size of VulnCheck's list of Anthropic-attributed CVEs after the next few Patch Tuesdays, the first direct count of Mythos findings reaching public disclosure.
  • Whether GitHub's CVE issuance holds its year-to-date pace into the second half of 2026 or falls back as models finish passes over new code bases.
  • Whether the share of new CVEs with evidence of exploitation rises with the count; a flat share would keep the extra volume a triage cost.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories