Researchers at Google said that they have discovered the first vulnerability using a large language model which is an exploitable stack buffer underflow in SQLite.
According to a blog post, Google said it believes the bug is the first public example of an AI tool finding a previously unknown exploitable memory-safety issue in widely used real-world software.
The vulnerability was found in SQLite, an open source database engine popular among developers.
Google researchers reported the vulnerability to SQLite developers in early October, who fixed it immediately. As the issue was found before it appeared in an official release it did not impact SQLite users.
Google claimed the development as an example of “the immense potential AI can have for cyber defenders.”
Google researchers said that finding vulnerabilities in software before it is even released, means that there’s no scope for attackers to compete: the vulnerabilities are fixed before attackers even have a chance to use them.
The effort is part of a project called Big Sleep, which is a collaboration between Google Project Zero and Google DeepMind. It evolved out of a past project that started work on vulnerability research assisted by large language models.
A key motivating factor for Big Sleep has been the continued in-the-wild discovery of exploits for variants of previously found and patched vulnerabilities.

















Comments