Models

Google Ships Gemini 3.8 Flash and a Cybersecurity-Only Variant

Google's third Flash release in six weeks keeps pricing at $0.75 per million input tokens while adding a defender-only cybersecurity variant that patched Chrome vulnerabilities at 2.6x the rate of larger commercial models.

Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
Introducing Gemini 3.8 Flash and 3.8 Flash CyberAI-generated
By Rebecca Stone4 min read

Updated

Why it matters

  • Gemini 3.8 Flash is priced at $0.75 per million input tokens and $3.75 per million output tokens, matching 3.7 Flash.
  • Gemini 3.8 Flash Cyber achieved 47.2% pass@1 on Collinear's CWE-Bench patching benchmark, near a leading frontier model's 47.8%, and found a critical Google Cloud vulnerability in under 2 hours.
  • Flash Cyber is available only to vetted government authorities, critical infrastructure operators, and software maintainers through Google's new Fairwind Program.

Google has released Gemini 3.8 Flash, its "best reasoning and coding model yet," at the same price as its predecessor: $0.75 per million input tokens and $3.75 per million output tokens. The launch, Google's third Flash release in six weeks, arrives alongside a second variant, Gemini 3.8 Flash Cyber, a cybersecurity-specialized model restricted to vetted defenders through a new access program called Fairwind.

The release matters for two markets at once. Flash-class models are the workhorses of enterprise AI deployments, where per-token cost determines viability at scale, and the benchmarks Google cites position 3.8 Flash against larger, more expensive frontier models. The Cyber variant addresses a more contested policy area: whether AI vendors will grant offensive-capable security tools broadly or keep them behind gated programs.

Built for long-horizon coding and agents

Google claims substantial gains over 3.7 Flash, released three weeks ago, often approaching higher-cost frontier models. On DeepSWE v1.1, a long-horizon software engineering benchmark, the company says 3.8 Flash "outperforms most larger frontier models in autonomously solving complex engineering problems end to end, only at a fraction of the cost."

The model also targets specialized professional domains. Google reports that 3.8 Flash beats 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark, and scores 54.9% on HLE-Verified, a benchmark testing multi-step reasoning across STEM, humanities, and professional fields.

The performance gains come with a trade-off. Google is explicit that "3.8 Flash works harder" — executing extra reasoning steps, calling tools iteratively, and sometimes consuming more tokens to maximize performance at higher effort levels. Developers who prioritize compute efficiency can use lower effort levels or stay on Gemini 3.7 Flash, which Google says remains fully supported for efficiency-first workloads.

Flash Cyber: vulnerability discovery and automated patching

The more notable release is Gemini 3.8 Flash Cyber. On CyberGym, a standard industry benchmark for autonomous vulnerability discovery, Google says the model surpasses both 3.5 Flash Cyber and significantly larger frontier models. CyberGym focuses on C/C++ codebases, so Google also evaluated the model against an internal benchmark spanning vulnerabilities across complex codebases written in 20 programming languages. There, the model reaches a success rate exceeding 70%, which Google describes as an impressive leap over its previous models.

On patching, Google cites CWE-Bench, an external benchmark run by Collinear. Gemini 3.8 Flash Cyber achieves a pass@1 of 47.2%, nearly matching a leading frontier model at 47.8% — but at what Google calls a significantly lower cost, placing the model on the Pareto frontier of price versus performance.

Google framed the design choice as deliberately defensive: "This is why we have invested in vulnerability fixing from the start, and prioritized it over offensive capabilities like exploitation."

Already deployed inside Google

Google says it is already using 3.8 Flash Cyber to secure its own code, and the internal results are the strongest evidence in the announcement. The Chrome Security team found the model produced 2.6 times more correct vulnerability patches for Chrome than the best commercial models, which Google notes are much larger. Google's Cloud Vulnerability Research team used the model to find a critical foundational vulnerability in less than 2 hours — research and discovery that usually takes months.

External partner results back the claims. Wiz, the cloud security company Google is acquiring, found that Gemini 3.8 Flash Cyber achieves 7.5–9.7% higher recall on its internal penetration testing benchmark at 2.3–5.2x lower cost compared to other leading frontier models.

Safety posture and availability

Google says 3.8 Flash ships with safeguards against misuse in chemical, biological, radiological, and nuclear (CBRN) domains and cyber offense, in line with its Frontier Safety Framework. Flash Cyber carries more permissive cybersecurity mitigations, which is why access is limited to trusted defenders — government authorities, critical infrastructure operators, and software maintainers, who can apply through the Fairwind Program.

The company also reports a significant improvement in prompt injection robustness as measured by Gray Swan, the firm known for adversarial testing of language models.

Both variants share the same foundational intelligence, accelerated by what Google describes as long-running agentic loops that recursively evaluate and refine the underlying models. Google attributes the coding and reasoning gains partly to rigorous training in cybersecurity — a domain demanding enough that it appears to have raised general capabilities.

Availability is broad. Developers can build with 3.8 Flash through the Gemini API via Google AI Studio and Android Studio, or in agent-first workflows in Google Antigravity and UI generation in Stitch. Enterprises get access through Gemini Enterprise. Consumers with Google AI Pro and Ultra subscriptions can use it in the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.

The pace itself is the story to watch: three Flash releases in six weeks, each holding price flat while closing the gap with frontier models, puts pressure on competitors whose mid-tier pricing assumes a performance discount. And with Flash Cyber, Google has staked out a model for restricted security AI — frontier capability, gated distribution — that regulators and rivals will both study.

Original: blog.google

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

135 articles

Related articles

  1. Google Releases Gemini 3.5 Flash Cyber for Vulnerability Hunting
  2. Google Launches Gemini 3.1 Flash-Lite Starting at $0.25 Per Million Tokens
  3. Google Ships Gemini 3.5 Flash, Promises Pro Model Next Month
  4. Google Launches Gemini 3 Pro at $2/Million Input Tokens
  5. Google Ships Gemini 3.1 Pro, More Than Doubling Reasoning Score

« Previous articleNext article »