# Google presents Gemini 4 Argon, a model that finds, validates and patches software vulnerabilities, first for trusted cyber defenders > Google announced Gemini 4 Argon on 30 September 2026, rolling it out through its Fairwind Program before paid API and AI Ultra access. What the announcement states. FireAI Security & Research Team (HisnLabs) ยท Published 2026-10-02 Canonical: https://hisnlabs.com/en/news/google-gemini-4-argon-finds-validates-patches-vulnerabilities Google announced Gemini 4 Argon on 30 September 2026 and describes it as a frontier model that can autonomously find, validate and patch critical software vulnerabilities [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). It is rolling out first to a set of trusted cyber defenders through Google's Fairwind Program [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). The announcement matters to Mac users as a statement about how quickly flaws in everyday software may be found, on either side. ## Background Google presents Argon as delivering frontier performance in complex workflows across software engineering, enterprise knowledge work such as legal and finance, and cybersecurity defense [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). Help Net Security reports the same announcement on 1 October 2026 and frames the security capability as locating critical vulnerabilities, validating them and patching them without human help [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). ## What the announcement states On the test named CWE-bench, which measures fixes for software vulnerabilities, Google reports a top score of 68 percent that ties for first place [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). Help Net Security adds that Google says the model found a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide, one that earlier frontier models had missed [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). Google states that it is strengthening safeguards in four areas: defending against misuse, prompt injection attacks, monitoring for misalignment and hardening systems [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). Help Net Security reports that Google is also strengthening safeguards against cyber and chemical, biological, radiological and nuclear misuse, tested by internal and external red teams [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). Availability follows a phased approach. Google writes that safely releasing frontier capabilities at this level requires one, and that broader access starts with paid API customers and Google AI Ultra subscribers [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). The introductory price is $2 per million input tokens and $10 per million output tokens, and the output limit rises from 64,000 tokens to 1 million [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). > FireAI, the on-device firewall for macOS developed by HisnLabs, can check the apps it has seen on the network against public vulnerability databases and list those that need an update. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users The announcement is about defenders first: the Fairwind Program is the initial access channel, and general access comes later [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). The sources do not say when any person outside the program can use the vulnerability capability, and they do not report a flaw in Mac software found by the model. A model that locates and patches flaws without human help changes how fast patches may arrive. It does not change what a Mac user controls: whether an installed app is current. The announcement does not claim that attackers lack similar tools, and Google's own safeguards list names misuse as a risk it is working on [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). ## Recommendations 1. Install operating system and app updates when they are released; faster flaw discovery shortens the useful gap between a patch and its adoption. 2. Keep a list of the apps that connect to the internet on the Mac and update those first, since they are the ones a remote party can reach. 3. Read Google's own announcement for the terms of access before relying on the model for security work; the announcement states that access is phased [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/). 4. Treat claims of a score on a test such as CWE-bench as the vendor's report, as the sources attribute the figure to Google [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). ## Relevance to FireAI FireAI does not use Gemini, and nothing in the announcement concerns it. A related feature is [apps that need an update](https://hisnlabs.com/en/docs/apps-that-need-an-update): with threat data turned on, FireAI looks up the version of each app it has seen on the network in public vulnerability databases, NIST's NVD and CISA's list of flaws known to be exploited, and lists the apps that have known security flaws. The lookup sends only the product name and version, and the user's connections are never sent. FireAI does not find new vulnerabilities, does not write or apply patches, and does not update apps for the user: it points to the app and the user updates it from the app's own website or the App Store. It checks well-known apps it has seen connecting, not every app on a disk, and it does not run or evaluate AI models that look for software flaws. > A patch only helps once it is installed. FireAI lists apps with known flaws when threat data is on, and asks before an app reaches a destination it has no rule for. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations Both sources relay Google's own account. The 68 percent score, the healthcare example and the claim that earlier frontier models missed the flaw are Google's statements, and this item has no independent test of Argon [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). The sources do not name the healthcare product, the vulnerability or the date it was fixed. The two sources describe the access plan with small differences in wording: Google's post says the model is rolling out to trusted cyber defenders, while Help Net Security reports developers, enterprises and consumers getting it later, starting with paid API customers and Google AI Ultra subscribers [[1]](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) [[2]](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/). Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [Google, 30 September 2026: Gemini 4 Argon, our next era of frontier intelligence](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/) - [Help Net Security, 1 October 2026: Google says Gemini 4 Argon can find and patch critical software flaws](https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/)