• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to primary sidebar

DigiBanker

Bringing you cutting-edge new technologies and disruptive financial innovations.

  • Home
  • Pricing
  • Features
    • Overview Of Features
    • Search
    • Favorites
  • Share!
  • Log In
  • Home
  • Pricing
  • Features
    • Overview Of Features
    • Search
    • Favorites
  • Share!
  • Log In

Google DeepMind unveils CodeMender, an AI agent that autonomously patches software vulnerabilities and validates whether proposed changes preserve functionality

October 8, 2025 //  by Finnovate

Alphabet Inc.’s Google DeepMind lab shared results for CodeMender, an AI-powered agent that automatically detects, patches and rewrites vulnerable code to prevent future exploits. The aim is to debug and repair complex security flaws autonomously across massive codebases. While still only in a research phase, CodeMender has already submitted 72 security fixes to open-source projects, including those spanning more than 4.5 million lines of code. According to DeepMind, CodeMender’s AI-powered agent helps developers and maintainers focus on what they do best — building good software — by automatically creating and applying high-quality security patches. CodeMender is designed to be both reactive and proactive by instantly patching discovered vulnerabilities and also rewriting existing code to eliminate entire classes of flaws. In one example, the agent applied “-fbounds-safety” annotations to the libwebp image compression library, the same library exploited in a 2023 zero-click iOS attack. In doing so, it rendered similar buffer overflow vulnerabilities “unexploitable forever,” according to DeepMind researchers. Under the hood, CodeMender uses a suite of tools including static and dynamic analysis, fuzzing, symbolic reasoning and an “LLM judge” that validates whether proposed changes preserve functionality. The system can self-correct automatically before surfacing its final patch for human review when the validation detects an issue and all changes are verified for correctness, adherence to style guidelines and lack of regressions before submission.

Read Article

Category: Essential Guidance

Previous Post: « LiveOak Bank implements Infinant’s cloud-native platform to scale embedded finance across vertical SaaS partners; maintaining bank-controlled ledger and regulatory compliance.
Next Post: Google is tightening control over Android, introducing developer verification to enhance security and reduce risks from malicious apps »

Copyright © 2025 Finnovate Research · All Rights Reserved · Privacy Policy
Finnovate Research · Knyvett House · Watermans Business Park · The Causeway Staines · TW18 3BA · United Kingdom · About · Contact Us · Tel: +44-20-3070-0188

We use cookies to provide the best website experience for you. If you continue to use this site we will assume that you are happy with it.