logo

Google claims Big Sleep 'first' AI to spot freshly committed security bug that fuzzing missed

ID: 5e2c052d-0987-5f5c-ac69-3c50d54e75e5

STIX ID: report--5e2c052d-0987-5f5c-ac69-3c50d54e75e5

Feed Name: The Register (Security)

Threat Score
30/100

Date Published: 2024-11-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Google's Project Zero / DeepMind research agent 'Big Sleep' (based on Gemini 1.5 Pro) identified a stack buffer underflow in SQLite—an exploitable memory-safety issue tied to an accidental use of -1 as an array index—which could allow crashes or possible code execution. The issue was found in commit history during a research review, reported, and fixed the same day before an official release; fuzzing had not found the bug. The write-up emphasizes the defensive potential of AI for finding hard-to-fuzz memory-safety bugs and contrasts Big Sleep with other AI-assisted tools focused on different bug classes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.