Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Dragon Breath uses RONINGLOADER to disable security tools and introduces Gh0st RAT

Turning submarine cables into environmental monitoring systems

International research on population and family dynamics

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Adoption of Rust reduces Android memory safety bugs to less than 20% for the first time
Identity

Adoption of Rust reduces Android memory safety bugs to less than 20% for the first time

userBy userNovember 17, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 17, 2025Ravi LakshmananVulnerabilities / Mobile Security

Google revealed that the number of memory safety vulnerabilities has dropped below 20% for the first time as the company continues to adopt the Rust programming language in Android.

“We adopted Rust for security and saw a 1,000x reduction in memory safety vulnerability density compared to Android’s C and C++ code,” said Google’s Jeff Vander Stoep. “But the biggest surprise is the impact Rust has had on software delivery.” “Rust changes reduced rollback rates by a factor of 4 and reduced time spent on code reviews by 25%, making a safer method a faster method.”

The development comes a little more than a year after the tech giant announced that its transition to Rust had reduced memory safety vulnerabilities from 223 in 2019 to fewer than 50 in 2024.

DFIR retainer service

The company noted that Rust code requires fewer revisions, approximately 20% fewer revisions than C++ code, contributing to lower rollback rates, thereby increasing overall development throughput.

Google also said it has plans to extend Rust’s “security and productivity benefits” to other parts of the Android ecosystem, including the kernel, firmware, Nearby Presence, critical first-party apps like Message Layer Security (MLS), and Chromium, which has replaced its PNG, JSON, and web font parsers with Rust’s memory-safe implementations.

He further stated that memory safety features built into programming languages ​​are only one part of a comprehensive memory safety strategy, emphasizing the need for a defense-in-depth approach.

As an example, Google highlighted the discovery of a memory safety vulnerability (CVE-2025-48530, CVSS score: 8.1) in CrabbyAVIF, an insecure AVIF (AV1 image file) parser/decoder implementation in Rust, that could potentially lead to remote code execution. This linear buffer overflow flaw was never publicly disclosed, but was patched by Google as part of the August 2025 Android security update.

CIS build kit

Further analysis of this “near-miss” vulnerability revealed that it is made unexploitable by Scudo, Android’s dynamic user-mode memory allocator designed to address heap-related vulnerabilities such as buffer overflow, use-after-free, and double-free without sacrificing performance.

Google emphasized that insecure Rust is “already highly secure,” saying it has a significantly lower density of vulnerabilities than C or C++, and adding that incorporating “insecure” blocks of code into Rust does not automatically disable the programming language’s safety checks.

“While C and C++ are here to stay, and both software and hardware safety mechanisms remain important for defense-in-depth, the move to Rust is a different approach where a safer path is clearly more efficient,” the company said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article‘Buy Now, Pay Later’ is expanding fast, and that should worry everyone
Next Article Launch of the “Choose Europe for Science” initiative
user
  • Website

Related Posts

Dragon Breath uses RONINGLOADER to disable security tools and introduces Gh0st RAT

November 17, 2025

RondoDox exploits unpatched XWiki servers to draw more devices into botnet

November 15, 2025

Five Americans plead guilty to helping North Korean IT workers break into 136 companies

November 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Dragon Breath uses RONINGLOADER to disable security tools and introduces Gh0st RAT

Turning submarine cables into environmental monitoring systems

International research on population and family dynamics

Launch of the “Choose Europe for Science” initiative

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.