English

SecurityGoogleCodeMender

Google Applies 72 Security Fixes to OSS Using AI Agent CodeMender

This article is a translation. Read the Japanese original

Google has shared the initial results of "CodeMender," an AI-powered agent designed to improve code security. The company stated that AI is assisting in the discovery and remediation of vulnerabilities that are difficult to address using traditional automated methods such as fuzzing.

CodeMender employs two primary approaches: rapid response to new vulnerabilities and proactive security hardening by rewriting existing code. Over a six-month development period, it has successfully upstreamed 72 security fixes to open-source software, including projects with as many as 4.5 million lines of code.

Technically, the agent utilizes the reasoning capabilities of Gemini Deep Think models to perform autonomous debugging and fixing. The agent performs inference before making code changes and automatically verifies that no regressions have occurred. Human review is limited to high-quality patches that correct the root cause and are functionally correct.

Specifically, the agent identifies root causes using tools such as debuggers and source code browsers. For example, one case demonstrated identifying a stack management error during XML element parsing from a heap buffer overflow report, which was then fixed with a change of only a few lines. Additionally, the agent created non-trivial patches, such as modifying the C code generation system within a project to resolve complex object lifetime issues.

Furthermore, CodeMender is equipped with the ability to rewrite existing code using safer data structures and APIs. For instance, in an effort to prevent the exploitation of buffer overflows and underflows, the agent applied "-fbounds-safety" annotations to parts of the widely used image compression library "libwebp," adding compiler-based bounds checking.


Source: CodeMender: an AI agent for code security (HN 199pt, 29 comments) (HN Search (backfill), 2025-10-07)