Chronicle/Defense & research

Anthropic reports over 500 human-validated high-severity open-source vulnerabilities found with Claude Opus 4.6

DefensePaperSignificance assistant-drafted

Anthropic's Frontier Red Team reports that Claude Opus 4.6, run in a VM with standard tools but no custom harness, found and validated more than 500 high-severity vulnerabilities in open-source software, focusing on memory corruption that can be confirmed with sanitizers. Every bug was validated before reporting, initially by Anthropic researchers who also wrote patches and later with external researchers; examples include Ghostscript, OpenSC and CGIF.

Why it matters

It shows a general-purpose model finding bugs in heavily fuzzed code out of the box and describes the validation effort needed to avoid burdening maintainers.

Key facts

As stated in the sources, with where to find them.

  • More than 500 high-severity vulnerabilities found and validated; reporting had begun and initial patches were landing.Introduction
  • Claude ran in a VM with coreutils, Python, debuggers and fuzzers but no task-specific instructions or custom harness.Section 'Setup'
  • For the initial findings, Anthropic security researchers validated each vulnerability and wrote patches by hand; external researchers were added as volume grew.Section 'Setup'

Findings that cite this record

Key questions this bears on

Sources

Related records