International Edition
Latest News
Technology

Google Uses Gemini AI to Translate Legacy C Code to Memory-Safe Rust

Google security engineers have validated an automated pathway for eliminating legacy memory vulnerabilities from infrastructure by using Gemini to translate C codebases into memory-safe Rust. Software engineers Bastian Kersting and Max Hils targeted giflib, a 3,000-line image-processing library…

Google Uses Gemini AI to Translate Legacy C Code to Memory-Safe Rust

Google security engineers have validated an automated pathway for eliminating legacy memory vulnerabilities from infrastructure by using Gemini to translate C codebases into memory-safe Rust. Software engineers Bastian Kersting and Max Hils targeted giflib, a 3,000-line image-processing library that routinely decodes untrusted user input without sandboxing. By delivering an ABI-compatible drop-in Rust library, the team decommissioned process isolation sandboxes, maintained runtime latency parity, and neutralized an unpatched heap write zero-day before its public cataloguing as CVE-2026-26740.

Automated Three-Stage Migration and Feedback Loops

Memory corruption bugs account for approximately 70 percent of severe security vulnerabilities in mature C and C++ stacks. Rather than relying on multi-year manual rewrites or runtime bounds checking, Kersting and Hils deployed a three-stage automated migration process driven by an autonomous feedback loop.

Initially, the engineers utilized a single-shot prompt with Gemini to translate the entire C library logic into Rust. To replace the existing shared object transparently without breaking downstream callers, the engineers preserved the original exported symbols and struct definitions. Modeling the foreign function interface introduced unsound raw pointer semantics during initial iterations, which required human experts to refine pointer ownership and lifetime invariants. Finally, automated differential testing engines detected behavioral discrepancies and fed failure traces back to the model for iterative patch synthesis.

Verification Through Mass-Scale Regression and Fuzzing

Deploying AI-generated code to mission-critical infrastructure required establishing strict semantic equivalence against the historical C implementation. The team instituted a validation pipeline featuring mass-scale regression decoding across more than 30 million real-world GIF assets to ensure bit-for-bit rendering parity.

Running concurrently over a span of six days, an automated differential fuzzer continuously executed parallel rounds of both runtimes, recording 200 million iterations without detecting any functional divergence. Adversarial LLM evaluation prompts analyzed both repositories to uncover latent behavioral bifurcations. This testing pipeline successfully uncovered an unaddressed edge case inside the LZW decompressor and highlighted an embedded legacy out-of-bounds write originating from a prior internal modification to the native C codebase.

Preempting CVE-2026-26740 in Staging

The definitive validation of the project materialized during staging when an external security researcher uncovered an out-of-bounds heap write in upstream giflib, tracked as CVE-2026-26740. Production nodes running Google’s compiled Rust replacement proved structurally immune to the flaw prior to public disclosure. This outcome demonstrates that architectural language migrations inherently preempt entire vulnerability classes.

Guavy Wire
Photo: guavy.com

Replacing C libraries with Rust frequently raises concerns regarding runtime overhead introduced by mandatory bounds checks. Telemetry gathered from production image decoding clusters worldwide verified that the Rust binary performed identically to the original C executable in terms of runtime speed. Because memory safety guarantees shifted directly into the type system, platform engineers dismantled legacy operating system sandboxes previously required to isolate image decoding tasks. Removing that process isolation boundary produced a marked reduction in p99 tail latency.

Despite these efficiency gains, the authors emphasized that artificial intelligence translations are not a hands-off panacea. Sustained maintenance divergence arises whenever upstream repositories introduce new features or architectural changes, complicating efforts to fork upstream C codebases into Rust repositories. Human domain knowledge remains essential for foreign function interface wrappers to avoid lifetime leaks and preserve thread-safety guarantees.

Adding Structured Output to Google Gemini / GenAI – Live Coding with Rust Explained
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”