logo

Securing tomorrow's software: the need for memory safety standards

ID: c4d55f52-2305-522d-9b45-85ebfe1c3886

STIX ID: report--c4d55f52-2305-522d-9b45-85ebfe1c3886

Feed Name: Google Online Security Blog

Date Published: 2025-02-25

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

The post advocates a shift to standardized memory safety across the software industry, proposing a technology-neutral framework with tiered assurance levels (akin to SLSA) to enable objective assessment, procurement incentives, and policy alignment. It highlights growing use of memory-safe languages (e.g., Rust, Kotlin) and complementary hardware protections (ARM MTE, CHERI), calls for practical guidance on integrating unsafe code where necessary, and outlines Google’s commitments (Secure by Design whitepaper, memory safety strategy, prioritizing memory-safe languages, and deploying hardened libc++).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.