Google has unveiled CodeMender , a new AI-powered agent that automatically improves software security by identifying and fixing vulnerabilities . This initiative addresses the growing gap between rapid, AI-assisted discovery of flaws security and the time-consuming manual effort required to fix them.

Leveraging advanced artificial intelligence, CodeMender not only reacts to new threats, but also proactively refactors existing code to eliminate entire classes of vulnerabilities. In its first six months, the project has already helped deliver 72 security fixes to various open-source projects (some with codebases as large as 4.5 million lines).
See also: Google Opal: The AI vibe-coding app in 15 more countries
This growth comes as AI tools, such as Big Sleep and OSS-Fuzz , accelerate the discovery of zero-day vulnerabilities, creating a volume of patches that is difficult for developers to manage.
Google AI Agent CodeMender
CodeMender operates as a standalone agent powered by Google's Gemini Deep Think. It is equipped with a range of sophisticated tools that allow it to analyze software, fix complex issues, and validate its own changes.
This ensures that any proposed fix is correct and does not introduce new problems or regressions. The agent's overall approach combines reactive patching of new vulnerabilities with proactive code writing to adopt more secure practices.
See also: Google fixes serious Chrome vulnerabilities
To identify the true origin of a security flaw, CodeMender uses advanced program analysis techniques, including static and dynamic analysis, fuzzing, and differential testing.

For example, in a case involving a heap buffer overflow crash, the agent looked beyond the immediate error and identified the root cause of the problem as incorrect stack management of XML elements during parsing. It then designed an effective fix. The system also uses specialized multi-agent systems , including an LLM-based critique tool that analyzes code modifications to prevent regressions. At the same time, it allows the agent to self-heal.
Beyond fixing individual bugs, CodeMender is designed to proactively harden codebases against future attacks. In one notable implementation, the agent was deployed on the libwebp image compression library. It systematically implemented -fbounds-safety annotations, a security feature that adds bounds checks to the code. According to Google, this single measure would have rendered the notorious libwebp vulnerability (CVE-2023-4863), which was used in a zero-click iOS exploit, unexploitable.
See also: Google's new Gemini uses the browser like you do

While the early results are encouraging, Google is proceeding cautiously, ensuring that any AI-generated fixes are reviewed by human researchers before being submitted. The ultimate goal is to improve the system and release it as a public tool for all software developers. This marks an important step in using AI to strengthen software security. Google plans to share more details in technical documents and reports in the coming months.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
