Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google DeepMind released Gemini 3.5 Flash Cyber, a lightweight AI built atop 3.5 Flash and designed to discover, validate, and patch software vulnerabilities via the CodeMender agent.
- Due to the model's dual-use nature, DeepMind is limiting access to governments and trusted partners in a pilot program, per Gemini Security Lead Raluca Ada Popa and VP of security and privacy Four Flynn.
- On the V8 JavaScript Engine, Gemini 3.5 Flash Cyber found 55 unique confirmed vulnerabilities — versus 47 for 3.5 Flash and 36 for Anthropic's Claude Opus 4.6 — including 10 issues no other model caught.
- Stress-testing on Google Chrome and Apple Safari showed the model significantly outperformed Gemini 3.5 Flash, 3.6 Flash, and Claude Opus 4.6 at uncovering new vulnerabilities.
- The model produced a 100% reliable remote-code execution exploit during real-world testing on public APIs and a production service, bypassing standard mitigations like ASLR and W^X.
- The cyber launch came alongside Gemini 3.6 Flash and 3.5 Flash-Lite, while Google separately routes CodeMender's capabilities to enterprise customers through the Gemini Enterprise Agent Platform.
Why it matters: Google is gating this model to governments and vetted partners because of its dual-use potential, even as it outperforms Anthropic's Claude Opus 4.6 on vulnerability discovery (55 vs 36 V8 issues). Enterprise defenders get the patching capabilities separately via the Gemini Enterprise Agent Platform — meaning the restricted-access framing is partly a safety posture and partly a moat.


