Google Uses AI-Powered Code Review to Outpace Attackers Exploiting Stolen Source Code
Google Threat Intelligence has revealed details of an internal tool called the Agentic Vulnerability Discovery Harness (AVDH), built to help defenders find and fix security flaws faster than attackers can exploit them. The tool combines AI models with structured human expert oversight to analyse source code, a response to growing concerns that when proprietary code is stolen, attackers can use AI tools to find exploitable weaknesses at speeds defenders struggle to match.
According to Google, the results have been significant. In one incident response case involving stolen corporate repositories, AVDH identified more than 100 confirmed critical vulnerabilities within two days, a task that would normally take far longer through manual review. Over ten months of use, the tool has been applied to codebases spanning tens of millions of lines, running thousands of analysis pipelines and generating tens of thousands of findings. This work has already led to a dozen assigned CVEs in widely used web extensions and open-source projects, with more currently going through disclosure.
Google says AVDH is designed to work alongside its other scanning tools, such as CodeMender, to create layered protection. By sharing details of this architecture publicly for the first time, the company aims to help other defenders build similar AI-assisted review processes into their own security operations.