Google's Mandiant Launches AI-Powered Tool to Uncover Code Vulnerabilities Swiftly

August 19, 2026
Google's Mandiant Launches AI-Powered Tool to Uncover Code Vulnerabilities Swiftly
  • Google’s Mandiant unveiled the Agentic Vulnerability Discovery Harness (AVDH), an AI-driven pipeline of specialized agents that hunt for vulnerabilities in source code, and in a live investigation of stolen corporate repositories it found more than 100 verified, high-severity flaws in two days.

  • AVDH acts as a force multiplier, automating routine vulnerability discovery so human defenders can focus on complex exploit chains, business-logic flaws, and adversarial activity that require judgment.

  • Google Cloud described AVDH as a framework that blends multiple AI agents with human review to identify exploitable flaws across large codebases.

  • Policy context: the DMCA security-research exemption renewal window closes in late August, with comments due in late September, preserving anti-circumvention protections for 2027–2030 and potentially requiring new petitions for changes.

  • Chrome updates: version 152.0.7977.64 is available for Linux, with Windows and macOS builds 152.0.7977.64/.65; users can update via the browser settings or await broader rollout.

  • Author background notes accompany the piece, including security expertise and a lighthearted personal aside.

  • NIST SP 1353 draft outlines structured prompts for governance review, current-state and target-state CSF artifacts, with comments due in mid-October and a focus on mapping policies to remediation evidence.

  • The report lists high-severity fixes across ANGLE, WebGL, V8, WebRTC, Extensions, Autofill, GPU, Bluetooth, Sandbox, and Passwords, among others, including several buffer and use-after-free issues.

  • AVDH is designed as a sequential pipeline starting with threat modeling, followed by file-wide analysis to identify entry points, then deeper control-flow and data-flow analysis.

  • The article cites researchers to contextualize the vulnerabilities and assesses the security posture surrounding the Chrome update.

  • Two disclosed flaws can be triggered by visiting a malicious site, with sandboxing limiting impact but not guaranteeing safety.

  • Google notes no active exploitation has been disclosed, and detailed bug information is temporarily restricted until most users update.

Summary based on 7 sources


Get a daily email with more Tech stories

More Stories