Google Uses AI to Automatically Rewrite Critical C Libraries Into Rust, Fixing Zero-Day Before Disclosure

Gemini-powered migration of giflib eliminates memory bugs and process isolation sandboxes while preserving latency

By LineZotpaper
Published
Read Time2 min
Google security teams have successfully used its Gemini AI model to automatically translate a 3,000-line C library into safe Rust code, creating a drop-in replacement that eliminated an unpatched zero-day vulnerability — catalogued as CVE-2026-26740 — before it was publicly disclosed. The initiative targeted giflib, an image-processing library that often handles untrusted user input without sandboxing, and delivered an ABI-compatible Rust version that allowed the team to decommission process isolation sandboxes while maintaining latency neutrality.

The project, detailed by Google's bug hunters team, was carried out by software engineers Bastian Kersting and Max Hils. It follows a three-stage automated migration process designed around an autonomous feedback loop.

First, the team applied a single-shot prompt with Gemini to port the complete logic of the C library into Rust. Because the library needed to replace the existing shared object transparently without breaking downstream callers, the engineers retained the original exported symbols and struct definitions. Modelling the foreign function interface introduced unsound raw pointer semantics during initial iterations, requiring human experts to inspect and refine pointer ownership and lifetime invariants. Finally, automated differential testing engines detected behavioural discrepancies and fed the failure traces back to the model for iterative patch synthesis.

Memory corruption bugs represent roughly 70 per cent of severe security vulnerabilities in mature C and C++ stacks, according to Google. Rather than undertaking multi-year manual conversions or relying entirely on runtime bounds checking, the team demonstrated a novel pathway for eliminating legacy memory vulnerabilities at scale.

Deploying automatically generated code to mission-critical infrastructure required establishing semantic equivalence. The team delivered an ABI-compatible drop-in library written in Rust, neutralising the heap write zero-day prior to its public cataloguing.

Google framed the effort as a scalable alternative to the slow, manual rewrites that have characterised the industry's shift to memory-safe languages, suggesting AI-assisted translation could accelerate the elimination of entire classes of vulnerabilities across legacy infrastructure.

§

Analysis

Why This Matters

  • Demonstrates a practical, scalable method for translating legacy C codebases into memory-safe Rust, potentially reducing the security debt accumulated across decades of C and C++ software.
  • The ability to automatically fix a zero-day before public disclosure — while decommissioning resource-intensive sandboxes — sets a new benchmark for proactive vulnerability remediation at major tech companies.
  • If this approach proves repeatable, it could reshape how organisations prioritise memory safety investments, shifting from manual rewrites toward AI-assisted, fuzzer-validated migrations.

Background

Memory corruption bugs — buffer overflows, use-after-free errors, and similar flaws — have been the leading cause of severe vulnerabilities in C and C++ code for decades. Google, Microsoft, and other large software vendors have increasingly advocated for memory-safe languages such as Rust. However, rewriting millions of lines of existing, battle-tested C code manually is prohibitively expensive and slow. The giflib library, at roughly 3,000 lines, is a small but critical component that processes untrusted user input, making it a good candidate for an automated proof-of-concept. Google has previously used fuzzing extensively to find bugs; this project combines fuzzing with generative AI to fix them.

Key Perspectives

Google Security Team: The approach provides a viable path to eliminate entire classes of vulnerabilities at scale, reducing reliance on runtime guards like sandboxes and preserving performance characteristics. Software Engineering Community: The need for human oversight — particularly around pointer ownership and lifetime invariants — suggests fully autonomous migration remains elusive, but the iterative feedback loop between fuzzing and AI shows promise. Critics/Skeptics: Automatically generated code deployed to production raises questions about long-term maintainability, toolchain compatibility, and whether the technique can scale beyond carefully scoped libraries to large, tightly coupled codebases with complex concurrency or platform-specific dependencies.

What to Watch

  • Whether Google extends the approach to larger C libraries (e.g., libpng, libjpeg-turbo, or OpenSSL components) and publishes comparative security outcomes.
  • How the broader industry responds: will CI/CD toolchains incorporate similar AI-assisted migration pipelines?
  • The long-term maintenance burden of AI-generated Rust code — will it be auditable and modifiable by human engineers without degrading safety guarantees?

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.