AI-Assisted Bug Hunting Drives Record Surge in Software Flaws

AI chatbots are already enabling a dramatic increase in the discovery of software vulnerabilities, with major tech firms reporting record patch volumes. Microsoft issued fixes for 974 confirmed flaws in a single month, while Oracle and Google also shipped unprecedented numbers of patches. The total number of recorded vulnerabilities this year has nearly doubled compared to the same period last year, straining security teams and open-source maintainers.
The scale of the surge is striking when compared against recent history. As of mid-September this year, the CVE tracking project cve.icu had logged 66,401 confirmed vulnerabilities—nearly double the 33,512 recorded by the same date last year, and more than two and a half times the total for all of 2022. Individual vendors illustrate the trend: Oracle's July patch batch contained 1,448 fixes versus 309 a year earlier, while Google Chrome's two June releases combined for 1,072 patches, exceeding the total from its previous 23 major updates.
Experts remain divided on what this means. Researcher Jerry Gamblin argues that a higher CVE count reflects the system working—more known flaws, not necessarily more flaws—while Britain's National Cyber Security Center cautions that discovery alone improves nothing. The central concern is that security teams and open-source maintainers, already stretched thin, will be overwhelmed by the volume, leaving patches unapplied and attackers exploiting gaps faster than defenders can close them.
This surge could reshape the digital landscape in ways ordinary users may feel indirectly. If security teams become overwhelmed by patch volume, software users—from individuals to large enterprises—may face longer windows of exposure to known exploits, potentially increasing the risk of data breaches and ransomware attacks. Conversely, if AI-assisted discovery helps defenders stay ahead, the broader effect could be more resilient software over time. The outcome likely depends on whether investment in security staffing and patch deployment keeps pace with the accelerating rate of discovery.