Skip to content
AI Primer
release

Google launches Gemini 3.8 Flash Cyber for vulnerability repair

Google launched Gemini 3.8 Flash Cyber for vulnerability detection and automated patching. Google reports 86.2% on CyberGym and 47.2% on CWE-Bench; access begins with trusted Fairwind partners.

4 min read
Google launches Gemini 3.8 Flash Cyber for vulnerability repair
Google launches Gemini 3.8 Flash Cyber for vulnerability repair

TL;DR

  • Google shipped Gemini 3.8 as a broadly available Flash model and a defender-only Flash Cyber variant, in GoogleDeepMind's launch announcement.
  • Flash keeps Gemini 3.7 Flash's introductory API price, $0.75 per million input tokens and $3.75 per million output tokens, according to Google's price announcement.
  • Flash Cyber posts 86.2% on CyberGym vulnerability discovery and 47.2% pass@1 on CWE-Bench patching, per Google's benchmark post.
  • The public model takes smaller steps and verifies work more often, a behavior that can raise token use, as _philschmid's deployment note describes.
  • Google says its Chrome security team saw 2.6 times more correct vulnerability patches than with much larger commercial models in GoogleDeepMind's Chrome result.

The Cloud model reference assigns the public model a 1,048,576-token context window and a 65,536-token output cap. Simon Willison's same-day plugin release adds low, medium, and high thinking levels for gemini-3.8-flash, and records an HTML generation that took 13 seconds and cost 1.8 cents.

What shipped

Benchmarks that moved

First-party

Third-party evaluators

Customer-reported

Where it regressed

Google's benchmark chart shows no displayed 3.8-versus-3.7 regression, but the new Flash does not lead every cross-model result. Terminal-Bench 4.0 is 19.1% for Flash versus 51.8% for Claude Opus 5, a 32.7-point gap, while OSWorld 2.0 is 59.0% versus 75.4%, a 16.4-point gap.

Google's migration guide explicitly trades higher accuracy and reliability for higher token consumption relative to 3.7 Flash. It identifies lower thinking levels and 3.7 Flash as compute-efficiency options.

Under the hood

Google describes Flash and Flash Cyber as sharing foundational intelligence, with long-running agentic loops that recursively assess and refine outputs in Google's launch thread. Cyber adds training emphasis for vulnerability discovery and repair in the official launch post.

The public model's ID is gemini-3.8-flash. The Cloud model reference lists thinking, system instructions, structured output, and implicit context caching as supported, while Gemini Live API is not supported.

Where it shows up

Fairwind Program

Fairwind begins with national cyber authorities and essential-service providers such as telecommunications and energy operators, in GoogleDeepMind's access announcement. Google's program announcement pairs Flash Cyber with CodeMender, limits use to cybersecurity and incident-response employees, and requires multi-factor authentication.

Fixes run within an organization's cloud environment, according to GoogleDeepMind's security thread. Google also reported that its Cloud Vulnerability Research team found a critical foundational vulnerability in under two hours, work it said typically takes months, in Google's field-results post.

Further reading

Discussion across the web

Where this story is being discussed, in original context.

On X· 6 threads
TL;DR4 posts
What shipped4 posts
Benchmarks that moved3 posts
Under the hood1 post
Where it shows up2 posts
Fairwind Program2 posts
Share on X