Google has integrated OSS-Fuzz with CodeMender, its DeepMind-developed AI agent for code-security remediation, to move validated open-source vulnerability discoveries toward proposed fixes. OSS-Fuzz now supplies crash information and relevant source context to CodeMender, which investigates the root cause and generates a comprehensive patch. Proposed fixes are validated in an isolated environment to ensure they compile, eliminate the triggering crash, and do not regress functional tests; Google engineers will review patches during the beta phase, and repositories that disallow AI-generated submissions will be excluded.
The integration extends Google's AI-assisted fuzzing work, which previously produced 26 newly reported open-source vulnerabilities and increased successful coverage across C/C++ OSS-Fuzz projects from 160 to 272, adding more than 370,000 lines of code coverage. Earlier AI-generated or AI-enhanced fuzz targets found flaws missed by long-running human-authored targets, including CVE-2024-9143 in OpenSSL, reported in September 2024 and fixed the following month. The combined workflow aims to reduce the maintainer effort required both to identify and remediate fuzzing-detected security defects.

Track how attackers are adapting to this technology.
8 events from the most recent confirmed update back to the earliest known activity.
OSS-Fuzz open-sourced its framework for generating fuzz targets with LLMs. By then, the system was reliably producing targets with more meaningful coverage across 160 projects.
The OSS-Fuzz team announced an effort to use large language models to improve fuzzing coverage and find vulnerabilities before exploitation. It reported using an LLM to draft fuzz targets and address compilation issues.
Google launched OSS-Fuzz to identify and report bugs in open-source software.
Proposed CodeMender patches are tested in isolation for compilation, crash remediation, and functional regressions. During beta, Google engineers will review patches before delivery, and repositories that prohibit AI-generated contributions will not receive AI-generated submissions.
Google announced integration of OSS-Fuzz with DeepMind's CodeMender AI remediation agent. Validated fuzzing crashes and source context will be provided to CodeMender to analyze root causes and produce proposed patches.
Expanded AI-generated and AI-enhanced fuzzing uncovered 26 vulnerabilities in OSS-Fuzz projects that had already received hundreds of thousands of fuzzing hours, including a new cJSON vulnerability despite an existing human-written harness. The effort expanded automatic coverage gains to 272 C/C++ projects and added more than 370,000 lines of coverage.
A fix for the OpenSSL vulnerability CVE-2024-9143 was published after OSS-Fuzz reported the issue.
AI-assisted OSS-Fuzz identified and reported CVE-2024-9143 in OpenSSL, a critical library underpinning internet infrastructure. Google said the flaw had likely existed for two decades and would probably not have been found using existing human-written fuzz targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.