• About Us
  • Contact Us
  • Terms & Conditions
  • Privacy Policy
Technology Hive
  • Home
  • Technology
  • Artificial Intelligence (AI)
  • Cyber Security
  • Machine Learning
  • More
    • Deep Learning
    • AI in Healthcare
    • AI Regulations & Policies
    • Business
    • Cloud Computing
    • Ethics & Society
No Result
View All Result
  • Home
  • Technology
  • Artificial Intelligence (AI)
  • Cyber Security
  • Machine Learning
  • More
    • Deep Learning
    • AI in Healthcare
    • AI Regulations & Policies
    • Business
    • Cloud Computing
    • Ethics & Society
No Result
View All Result
Technology Hive
No Result
View All Result
Home Artificial Intelligence (AI)

Google’s AI Agent Automates Vulnerability Fixes by Rewriting Code

Adam Smith – Tech Writer & Blogger by Adam Smith – Tech Writer & Blogger
October 6, 2025
in Artificial Intelligence (AI)
0
Google’s AI Agent Automates Vulnerability Fixes by Rewriting Code
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Introduction to CodeMender

Google DeepMind has developed a new AI agent called CodeMender, designed to autonomously find and fix critical security vulnerabilities in software code. In the last six months, CodeMender has contributed 72 security fixes to established open-source projects. This innovative system addresses the challenging and time-consuming process of identifying and patching vulnerabilities, which can be difficult even with traditional automated methods like fuzzing.

The Challenge of Vulnerability Discovery

Identifying and patching vulnerabilities is a notoriously difficult and time-consuming process. While AI-based projects like Big Sleep and OSS-Fuzz have proven effective at discovering new zero-day vulnerabilities in well-audited code, this success creates a new bottleneck. As AI accelerates the discovery of flaws, the burden on human developers to fix them intensifies. CodeMender is engineered to address this imbalance by functioning as an autonomous AI agent that takes a comprehensive approach to fix code security.

How CodeMender Works

CodeMender operates by leveraging the advanced reasoning capabilities of Google’s recent Gemini Deep Think models. This foundation allows the agent to debug and resolve complex security issues with a high degree of autonomy. The system is equipped with a set of tools that permit it to analyze and reason about code before implementing any changes. CodeMender also includes a validation process to ensure any modifications are correct and do not introduce new problems, known as regressions.

Advanced Program Analysis

To enhance its code fixing effectiveness, the DeepMind team developed new techniques for the AI agent. CodeMender employs advanced program analysis, utilizing a suite of tools including static and dynamic analysis, differential testing, fuzzing, and SMT solvers. These instruments allow it to systematically scrutinize code patterns, control flow, and data flow to identify the fundamental causes of security flaws and architectural weaknesses.

Proactive Code Fixing

CodeMender is designed to proactively harden software against future threats. The team deployed the agent to apply -fbounds-safety annotations to parts of libwebp, a widely used image compression library. These annotations instruct the compiler to add bounds checks to the code, which can prevent an attacker from exploiting a buffer overflow to execute arbitrary code. This work is particularly relevant given that a heap buffer overflow vulnerability in libwebp was used by a threat actor in a zero-click iOS exploit several years ago.

Real-World Applications

In one practical example, CodeMender addressed a vulnerability where a crash report indicated a heap buffer overflow. Although the final patch only required changing a few lines of code, the root cause was not immediately obvious. By using a debugger and code search tools, the agent determined the true problem was an incorrect stack management issue with Extensible Markup Language (XML) elements during parsing, located elsewhere in the codebase. In another case, the agent devised a non-trivial patch for a complex object lifetime issue, modifying a custom system for generating C code within the target project.

Future Plans and Deployment

Despite these promising early results, Google DeepMind is taking a cautious and deliberate approach to deployment, with a strong focus on reliability. At present, every patch generated by CodeMender is reviewed by human researchers before being submitted to an open-source project. The team is gradually increasing its submissions to ensure high quality and to systematically incorporate feedback from the open-source community. The researchers plan to reach out to maintainers of critical open-source projects with CodeMender-generated patches and eventually release CodeMender as a publicly available tool for all software developers.

Conclusion

CodeMender represents a significant step forward in exploring the potential of AI agents to proactively fix code and fundamentally enhance software security for everyone. By leveraging advanced reasoning capabilities and program analysis, CodeMender can autonomously find and fix critical security vulnerabilities, reducing the burden on human developers and improving the overall security of software code.

FAQs

  1. What is CodeMender?
    CodeMender is an AI agent developed by Google DeepMind to autonomously find and fix critical security vulnerabilities in software code.
  2. How does CodeMender work?
    CodeMender operates by leveraging advanced reasoning capabilities and program analysis to debug and resolve complex security issues with a high degree of autonomy.
  3. What are the benefits of using CodeMender?
    CodeMender can reduce the burden on human developers to fix security vulnerabilities, improve the overall security of software code, and proactively harden software against future threats.
  4. Is CodeMender available for public use?
    CodeMender is currently being deployed in a cautious and deliberate manner, with a strong focus on reliability. The team plans to eventually release CodeMender as a publicly available tool for all software developers.
  5. How does CodeMender ensure the quality of its patches?
    CodeMender includes a validation process to ensure any modifications are correct and do not introduce new problems, known as regressions. Every patch generated by CodeMender is also reviewed by human researchers before being submitted to an open-source project.
Previous Post

AMD secures major AI chip contract from OpenAI

Next Post

Top AI AppSec Tools for 2025

Adam Smith – Tech Writer & Blogger

Adam Smith – Tech Writer & Blogger

Adam Smith is a passionate technology writer with a keen interest in emerging trends, gadgets, and software innovations. With over five years of experience in tech journalism, he has contributed insightful articles to leading tech blogs and online publications. His expertise covers a wide range of topics, including artificial intelligence, cybersecurity, mobile technology, and the latest advancements in consumer electronics. Adam excels in breaking down complex technical concepts into engaging and easy-to-understand content for a diverse audience. Beyond writing, he enjoys testing new gadgets, reviewing software, and staying up to date with the ever-evolving tech industry. His goal is to inform and inspire readers with in-depth analysis and practical insights into the digital world.

Related Posts

Neanderthals Intelligence
Artificial Intelligence (AI)

Neanderthals Intelligence

by Adam Smith – Tech Writer & Blogger
October 23, 2025
Druid AI Unveils AI Agent ‘Factory’ for Autonomy in the Real World
Artificial Intelligence (AI)

Druid AI Unveils AI Agent ‘Factory’ for Autonomy in the Real World

by Adam Smith – Tech Writer & Blogger
October 23, 2025
Five with MIT ties elected to National Academy of Medicine for 2025
Artificial Intelligence (AI)

Five with MIT ties elected to National Academy of Medicine for 2025

by Adam Smith – Tech Writer & Blogger
October 22, 2025
Africa’s Largest AI Gathering
Artificial Intelligence (AI)

Africa’s Largest AI Gathering

by Adam Smith – Tech Writer & Blogger
October 22, 2025
ChatGPT Atlas Blog Post
Artificial Intelligence (AI)

ChatGPT Atlas Blog Post

by Adam Smith – Tech Writer & Blogger
October 21, 2025
Next Post
Top AI AppSec Tools for 2025

Top AI AppSec Tools for 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Articles

AI Regulation Researchers Contribute to AI Act Commentary

AI Regulation Researchers Contribute to AI Act Commentary

March 26, 2025
Making AI More Trustworthy

Making AI More Trustworthy

May 1, 2025
The Next Big Thing in Business

The Next Big Thing in Business

February 26, 2025

Browse by Category

  • AI in Healthcare
  • AI Regulations & Policies
  • Artificial Intelligence (AI)
  • Business
  • Cloud Computing
  • Cyber Security
  • Deep Learning
  • Ethics & Society
  • Machine Learning
  • Technology
Technology Hive

Welcome to Technology Hive, your go-to source for the latest insights, trends, and innovations in technology and artificial intelligence. We are a dynamic digital magazine dedicated to exploring the ever-evolving landscape of AI, emerging technologies, and their impact on industries and everyday life.

Categories

  • AI in Healthcare
  • AI Regulations & Policies
  • Artificial Intelligence (AI)
  • Business
  • Cloud Computing
  • Cyber Security
  • Deep Learning
  • Ethics & Society
  • Machine Learning
  • Technology

Recent Posts

  • Lawsuit: Reddit caught Perplexity “red-handed” stealing data from Google results
  • OpenAI Expands OS Integration with New Acquisition
  • Neanderthals Intelligence
  • Druid AI Unveils AI Agent ‘Factory’ for Autonomy in the Real World
  • We Tested OpenAI’s Agent Mode by Letting it Surf the Web

Our Newsletter

Subscribe Us To Receive Our Latest News Directly In Your Inbox!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

© Copyright 2025. All Right Reserved By Technology Hive.

No Result
View All Result
  • Home
  • Technology
  • Artificial Intelligence (AI)
  • Cyber Security
  • Machine Learning
  • AI in Healthcare
  • AI Regulations & Policies
  • Business
  • Cloud Computing
  • Ethics & Society
  • Deep Learning

© Copyright 2025. All Right Reserved By Technology Hive.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?