1 SEP 2026 — Google patched 1,072 Chrome security bugs across two releases in June, more than the 1,036 it fixed in the preceding two years combined. A cryptographer's argument is that if AI closes vulnerabilities faster than they can be found, governments lose lawful hacking as a technique and ask for backdoors instead. The people who buy and sell exploits mostly disagree about the timing, not the direction.

The argument being made

Matthew Green, the Johns Hopkins cryptographer, has set out the case. Law enforcement and intelligence agencies rely on software flaws to get into devices belonging to people they have authority to investigate. That access depends on a supply of exploitable bugs. If machine-assisted auditing finds and fixes those bugs at industrial scale, the supply thins, and the agencies that depend on it will press for guaranteed access built into products.

The Chrome numbers make the argument concrete. Doug Turner, Chrome's director of engineering, described large language models as having shifted the economics of vulnerability discovery into an automated, industrial-scale operation. One agent-found flaw was a sandbox escape that had survived in the codebase for more than 13 years, which would have let a compromised renderer process read local files.

1,072Chrome bugs patched across two June releases
1,036Bugs patched in the preceding two years combined
13 yearsHow long one agent-found sandbox escape had survived
2014When the FBI popularised the original going-dark framing

Why this is a different going-dark from the last one

The phrase belongs to a specific fight. FBI director James Comey used it from 2014 to argue that end-to-end encryption in Signal, WhatsApp and iMessage was putting evidence beyond lawful reach, and the demand that followed was for exceptional access to encrypted messages.

What is being described now sits one layer down. Encryption protects data in transit and at rest. Device exploitation goes around it by taking the endpoint, where the plaintext is. That is why the encryption fight cooled without agencies losing access: the exploit route stayed open the entire time, and it is what agencies actually use.

The claim is that the workaround which made the original encryption fight survivable — device exploitation — may itself be closing. That would put the same demand back on the table with the alternative gone.

The objection that has the most force

Hamid Kashfi, founder of DarkCell, puts the counter-case in a single ratio: for every bug that AI finds and reports, roughly twenty are found and not reported. If that holds, automated discovery is not draining the pool. It is filling both sides of it, and the offensive side has no obligation to disclose.

The argument pivots on this empirical question. The same tools that let a vendor audit its own code let anyone else audit that code too. Whether the defensive or offensive use compounds faster is a question about incentives, disclosure norms and who has the compute, and nobody has published a measurement.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, makes a related point about the middle of the pipeline. Offence currently has the advantage, and patching remains slow and complicated. A bug fixed upstream is not fixed on a device until an update ships, downloads and installs, a gap measured in months across any real installed base.

What the exploit market says about itself

Paolo Stagno, chief technology officer at Crowdfense, which buys and sells exploits, describes the present state as the most democratic system available — meaning that a researcher anywhere can find a bug and be paid for it, without needing institutional backing. His caution is that this may not persist.

Luna Tong, a researcher formerly at bug-finding companies, describes the same period as a gold rush of bugs that is temporary. Both descriptions suggest automated discovery is currently harvesting decades of accumulated defects in mature codebases, which is a one-time yield. What happens after that backlog is cleared is a different regime, and neither the volume nor the direction of it has been observed yet.

Katie Moussouris, founder and chief executive of Luta Security, puts a horizon on the policy consequence: at least until after the next US presidential election before the intelligence community is hampered enough to push for backdoors. That is a forecast, not a finding, and it is the most concrete timing anyone quoted is willing to offer.

Why this matters in this region

Singapore, Malaysia, Indonesia and Vietnam have all legislated in the last few years on lawful access, platform obligations and cybersecurity duties, and none of those frameworks assumes a world where device exploitation stops working. A jurisdiction that has written its investigative powers around access-by-technique will face the same pressure to convert them into access-by-mandate, and will face it without the constitutional litigation history that shapes the argument in the United States.

The practical read for anyone building here is that the direction of travel favours designs where the operator cannot produce user content on demand, because that property is what makes a mandate expensive to impose. We reported that Singapore's Cyber Security Agency has been extending its critical-infrastructure framing to frontier AI systems, which is the same regulatory instinct arriving from the other direction.

None of this is settled. The Chrome figures are real and large, but the inference from them to a policy outcome depends on a ratio nobody has measured, a patching pipeline that has not improved, and a market whose own participants disagree.