Google has reported a significant reduction in memory safety vulnerabilities in Android, attributing this improvement to the adoption of the Rust programming language. According to Google, the proportion of memory safety bugs in Android has dropped below 20% for the first time, with Rust code demonstrating a 1000x reduction in vulnerability density compared to C and C++. The transition to Rust has also led to operational benefits, such as a lower rollback rate and faster code review cycles, and Google plans to expand Rust's use to additional components of the Android ecosystem, including the kernel, firmware, and key applications.
Security experts emphasize that secure coding should focus on principles like secure by default and secure by design, rather than simply identifying vulnerabilities. The integration of Rust into Android's codebase exemplifies how adopting memory-safe languages can serve as a practical application of these secure coding principles, reducing the burden on developers and improving overall software security. Google's experience also highlights the importance of a defense-in-depth approach, as even memory-safe languages like Rust can have vulnerabilities if unsafe code is used, as demonstrated by the discovery and patching of a buffer overflow in the CrabbyAVIF parser before public release.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
SC World published a podcast segment featuring Matias Madou discussing secure coding as an exercise in critical thinking rather than simply identifying vulnerabilities. The segment reflects ongoing industry discussion around improving software security practices.
Google reported that memory safety vulnerabilities in Android dropped to under 20% for the first time, attributing the improvement in part to increased adoption of the Rust programming language in new code. This marks a notable milestone in Android's secure development efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.