agentusecasesAll 965 use cases
Security, Science & Hardware

Hunt for unpatched vulnerabilities in SQLite commits

Google's Big Sleep agent reviewed recent SQLite commits starting from a patched bug and found an exploitable flaw, which was fixed before release.

Done withGemini

What they did
A Gemini 1.5 Pro agent ran in Project Zero's Naptime framework, which gives it a code browser, debugger, reporter tool and a sandbox for Python scripts. Researchers gave it a previously fixed SQLite bug, plus recent commit messages and diffs, and asked it to look for unresolved similar issues. It linked the old bug to other code, wrote a test case, triggered a crash, and produced a root-cause analysis.
How it went
It found a stack buffer underflow in seriesBestIndex, and SQLite fixed it the same day, before any release. Fuzzing for 150 CPU hours failed to rediscover it. The team calls Big Sleep highly experimental.
Worth knowing
The bug was in a development version only. The researchers think a target-specific fuzzer would likely be at least as effective as the agent today.

Try it yourself with Gemini

In this repo [path or URL], review the commits from the last [time period or number], starting with the fix for [known patched bug or commit]. Look for similar flaws that the fix may have missed, especially [bug class, e.g. memory safety]. Write a report listing each suspect commit, why it looks vulnerable, and how you'd confirm it. Don't modify the code or disclose anything publicly.

Read the original ↗

Source: scworld.com · Undated

Five of these in your inbox every morning

The best things people got an AI agent to do, each with the prompt to try it.

More like this