Google's CodeMender AI: Detects Vulnerabilities and Auto-Rewrites Code for Bulletproof Patches

Google's DeepMind introduced CodeMender, an AI agent that automatically detects vulnerabilities, generates high-quality patches, and rewrites code to prevent entire classes of exploits. Leveraging Gemini Deep Think models, it addresses root causes, uses an LLM-based critique tool to validate changes without regressions, and builds on existing tools like Big Sleep and OSS-Fuzz. This proactive and reactive approach helps secure codebases, allowing developers to focus on building software rather than manual fixes.


In the past six months, CodeMender has upstreamed 72 security patches to open-source projects, including those as large as 4.5 million lines of code. Google plans to collaborate with maintainers of critical OSS by providing these AI-generated patches for feedback, enhancing overall software safety and countering threats from cybercriminals and state actors.


Complementing this, Google launched an AI Vulnerability Reward Program (AI VRP) offering up to $30,000 for reporting AI issues like prompt injections and jailbreaks—excluding hallucinations or IP concerns—while updating its Secure AI Framework (SAIF) v2 to tackle agentic risks such as data leaks. This aligns with Anthropic's June 2025 findings on LLMs' potential malicious behaviors, emphasizing AI's role in empowering defenders.
NPAV offers a robust solution to combat cyber fraud. Protect yourself with our top-tier security product, Z Plus Security