Hunt for unpatched vulnerabilities in SQLite commits
Google's Big Sleep agent reviewed recent SQLite commits starting from a patched bug and found an exploitable flaw, which was fixed before release.
Done withGemini
- What they did
- A Gemini 1.5 Pro agent ran in Project Zero's Naptime framework, which gives it a code browser, debugger, reporter tool and a sandbox for Python scripts. Researchers gave it a previously fixed SQLite bug, plus recent commit messages and diffs, and asked it to look for unresolved similar issues. It linked the old bug to other code, wrote a test case, triggered a crash, and produced a root-cause analysis.
- How it went
- It found a stack buffer underflow in seriesBestIndex, and SQLite fixed it the same day, before any release. Fuzzing for 150 CPU hours failed to rediscover it. The team calls Big Sleep highly experimental.
- Worth knowing
- The bug was in a development version only. The researchers think a target-specific fuzzer would likely be at least as effective as the agent today.
Try it yourself with Gemini
In this repo [path or URL], review the commits from the last [time period or number], starting with the fix for [known patched bug or commit]. Look for similar flaws that the fix may have missed, especially [bug class, e.g. memory safety]. Write a report listing each suspect commit, why it looks vulnerable, and how you'd confirm it. Don't modify the code or disclose anything publicly.
1 more account of this
Source: scworld.com · Undated
Five of these in your inbox every morning
The best things people got an AI agent to do, each with the prompt to try it.
More like this
Race three models to build a Counter-Strike clone
InstantDB had Codex, Opus, and Gemini each try to build a multiplayer shooter.
Edit existing video clips with plain-English instructions
A creator tested Gemini Omni Flash over 36 hours, editing clips in place from typed instructions while preserving lighting and camera angle, with variable quality.
Solve open math problems autonomously
DeepMind's Aletheia agent on Gemini Deep Think was evaluated on 700 open Erdős problems and autonomously solved four.
Find a Linux vulnerability hidden for 23 years
An account of Claude Code uncovering a long-standing vulnerability in Linux.
- MathKernel
Give agents a multi-engine math kernel via MCP
MathKernel is an evidence-aware multi-engine mathematics kernel exposed as an MCP server for agents to use.
Design and build a robotic arm with no CAD experience
A builder used Claude Code with FreeCAD and Claude Vision to design, print, and assemble a 5-DOF servo arm with vision and voice control.