ZeroHour
The Recordpublished ()ingested

Google says ‘Big Sleep’ AI tool found bug hackers planned to use

criticalExploit / PoCimportance 60CVE-2025-6965

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-6965
Memory Corruption in SQLite < 3.50.2 Affecting Apple and Siemens Products

CVE-2025-6965 is a numeric handling flaw (CWE-197) in SQLite versions before 3.50.2 in which the number of aggregate terms in a query can exceed the number of available columns, resulting in memory corruption. An attacker triggers it by getting an application that embeds SQLite to execute crafted SQL: the vector is network-based and requires only low privileges, but with high attack complexity (CVSS 4.0 base 7.2), and successful corruption carries high integrity impact on the running process. Because SQLite is embedded in countless applications and operating systems, every deployment running SQLite older than 3.50.2 is affected, including Apple's iPhone OS, iPadOS, macOS, tvOS, visionOS and watchOS and Siemens' RUGGEDCOM CROSSBOW and SIDIS Prime, which bundle the library. The flaw is not on the CISA KEV list and no public proof-of-concept is known, but Google reported that its Big Sleep AI discovered the bug as hackers were preparing to exploit it, and EPSS assigns a 75.8% probability of exploitation within 30 days.

Do: Upgrade SQLite to version 3.50.2 or later in every bundled or embedded deployment, and apply the corresponding Apple OS and Siemens RUGGEDCOM CROSSBOW/SIDIS Prime updates as vendors publish fixed releases. Inventory which applications, devices and internet-facing services ship vulnerable SQLite and prioritize anything that processes untrusted SQL, given the very high EPSS score (75.8% within 30 days) and Google's report that attackers were preparing to exploit this bug. Where patching is delayed, review aggregate SQL queries for cases where aggregate terms exceed available columns as a triage measure.

7.276%
  • SQLite all versions before 3.50.2
  • Apple iPhone OS (iOS) versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • Apple iPadOS versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • +6 more
massbillions of devices worldwide (SQLite ships embedded in virtually every operating system, browser and application; Apple's active device base alone exceeds 1…
Full article455 words · extracted from therecord.media · click to collapse

Google said a large language model it developed to find vulnerabilities recently discovered a bug that hackers were preparing to use.

Late last year, Google announced an AI agent called Big Sleep — a project that evolved out of work on vulnerability research assisted by large language models done by  Google Project Zero and Google DeepMind. The tool actively searches and finds unknown security vulnerabilities in software.

On Tuesday, Google said Big Sleep managed to discover CVE-2025-6965 — a critical security flaw that Google said was “only known to threat actors and was at risk of being exploited.”

The vulnerability impacts SQLite, an open-source database engine popular among developers. Google claims it was “able to actually predict that a vulnerability was imminently going to be used” and was able to cut it off beforehand. 

“We believe this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild,” the company said. 

A Google spokesperson told Recorded Future News that the company’s threat intelligence group was “able to identify artifacts indicating the threat actors were staging a zero day but could not immediately identify the vulnerability.” 

“The limited indicators were passed along to other Google team members at the zero day initiative who leveraged Big Sleep to isolate the vulnerability the adversary was preparing to exploit in their operations,” they said.

The company declined to elaborate on who the threat actors were or what indicators were discovered. 

In a blog post touting a variety of AI developments, Google said since Big Sleep debuted in November, it has discovered multiple real-world vulnerabilities, “exceeding” the company’s expectations. 

Google said they are now using Big Sleep to help secure open-source projects and called AI agents a “game changer” because they “can free up security teams to focus on high-complexity threats, dramatically scaling their impact and reach.”

The tech giant published a white paper on how they built their own AI agents in a way that allegedly safeguards privacy, limits potential “rogue actions” and operates with transparency. 

Dozens of companies and U.S. government bodies are hard at work developing AI tools built to quickly search for and discover vulnerabilities in code. 

Next month, the U.S. Defense Department will announce the winners of a years-long competition to use AI to create systems that can automatically secure the critical code that undergirds prominent systems used across the globe.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-big-sleep-ai-tool-found-bug