
Gemini 3.8 Flash Cyber Fixes 2.6x More Chrome Bugs
Google's Gemini 3.8 Flash Cyber wrote 2.6x more correct Chrome patches than larger commercial models, and 3.8 Flash starts at $0.75 per million tokens.
Google Ships Its Third Flash Model in Six Weeks
Google announced Gemini 3.8 Flash and a specialised sibling, Gemini 3.8 Flash Cyber, on September 2, 2026. The headline claim is unusually specific for a model launch: Google's own Chrome Security team reports that 3.8 Flash Cyber produced 2.6 times more correct patches to real Chrome vulnerabilities than the best commercial models it tested, despite those models being considerably larger. That is a narrow, measurable result rather than a general capability claim, and it is the most interesting part of the release.
- Gemini 3.8 Flash launched September 2, 2026 at $0.75 per million input tokens and $3.75 per million output tokens, an introductory rate that runs through December 31, 2026
- Gemini 3.8 Flash Cyber produced 2.6x more correct Chrome patches than the best commercial models tested, according to Google's Chrome Security team
- Benchmarks: 47.2% pass@1 on CWE-Bench patching and 54.9% on HLE-Verified, with what Google describes as a significant jump in prompt-injection robustness on Gray Swan
- Availability: general 3.8 Flash is in AI Studio, Android Studio, Antigravity, Gemini Enterprise and the Gemini app; the Cyber variant is gated behind a new Fairwind Program
What Gemini 3.8 Flash Actually Improves
Google positions 3.8 Flash as its workhorse tier — the model most requests should route to — and describes the gains over 3.7 Flash as concentrated in software engineering, agentic task execution and multi-step reasoning in specialised domains. The published numbers back a mid-cycle upgrade rather than a generational leap: 47.2% pass@1 on CWE-Bench for vulnerability patching, and 54.9% on HLE-Verified across STEM, humanities and professional subjects.
The more consequential figure for anyone building agents may be the Gray Swan result. Gray Swan measures resistance to prompt injection, which is the failure mode that most reliably breaks an autonomous agent doing real work. Google reports a significant improvement there without publishing a headline percentage, so treat it as directional rather than settled. It is the axis worth watching as these models are handed longer-running tasks — the same tension we covered when Gemini 3.7 Flash arrived three weeks ago.
What Is Gemini 3.8 Flash Cyber?
Flash Cyber is a variant tuned specifically for vulnerability detection and automated patching. It is not a general-purpose release, and Google is not selling it openly. Access runs through the new Fairwind Program, which gives prioritised access to trusted government authorities, critical infrastructure operators and software maintainers.
That gating is a deliberate design decision. A model that is genuinely good at finding and fixing memory-safety bugs in a browser codebase is, by construction, also good at finding them. Restricting distribution to defenders and maintainers is the same reasoning that shaped Google's earlier work in this area — the Chrome bug-hunting agent that surfaced a 13-year-old flaw came out of the same team and the same premise: point the model at your own code first.
The 2.6x figure deserves one caveat. It comes from Google's Chrome Security team evaluating Google's model on Google's codebase, which is a vendor benchmark on home ground. It is a credible primary-source claim about a specific workload, and it is not yet an independent comparison.
How Much Does Gemini 3.8 Flash Cost?
$0.75 per million input tokens and $3.75 per million output tokens — but only until December 31, 2026. After that, standard pricing of $1.50 and $7.50 applies, exactly double. Anyone modelling costs on a long-lived agent workload should plan against the post-introductory number, not the launch one.
Held against the wider market, the introductory rate lands in the same neighbourhood as other mid-tier frontier options. We looked at that pricing floor when GPT-5.6 Sol dropped to $4 per million tokens; the direction of travel across vendors has been consistently downward for this class of model.
Where You Can Use It Today
Developers get 3.8 Flash through Google AI Studio, Android Studio and Antigravity. Enterprises get it in Gemini Enterprise. Consumers on AI Pro and Ultra plans see it in the Gemini app, AI Mode in Search, and Google Sheets. Defenders who want Flash Cyber apply to Fairwind.
For readers running local or hybrid setups, the practical read is that the cheap tier keeps getting more capable while the frontier tier stays expensive — which is broadly good news for the kind of always-on agent workloads our AI coverage tracks. More of the routine work fits in the cheap model every quarter.
Sources: Google — Introducing Gemini 3.8 Flash and 3.8 Flash Cyber — September 2, 2026; 9to5Google — September 2, 2026; Android Headlines — September 2, 2026.
More AI Stories

ChatGPT Health Connects Epic Records for Clinicians
OpenAI connected ChatGPT for Healthcare to Epic EHR records with read-only access, plus a data plugin covering PubMed, RxNorm and ClinicalTrials.gov.

Claude Fable 5.1 Doubles Science Scores, Cuts Costs
Claude Fable 5.1 more than doubles agentic science benchmarks and cuts typical workload costs 25%, with cache reads dropping to $0.25 per million tokens.

Tencent Hy4 Ships 770B Open Weights Under Apache 2.0
Tencent open-sourced Hy4 preview on August 28 with 770B total parameters, 49B active per token, a 1M-token context window and Apache 2.0 weights.
