Anthropic's Frontier Red Team reports that Claude Opus 4.6, run in a VM with standard tools but no custom harness, found and validated more than 500 high-severity vulnerabilities in open-source software, focusing on memory corruption that can be confirmed with sanitizers. Every bug was validated before reporting, initially by Anthropic researchers who also wrote patches and later with external researchers; examples include Ghostscript, OpenSC and CGIF.
Why it matters
It shows a general-purpose model finding bugs in heavily fuzzed code out of the box and describes the validation effort needed to avoid burdening maintainers.
Key facts
As stated in the sources, with where to find them.
- More than 500 high-severity vulnerabilities found and validated; reporting had begun and initial patches were landing.Introduction
- Claude ran in a VM with coreutils, Python, debuggers and fuzzers but no task-specific instructions or custom harness.Section 'Setup'
- For the initial findings, Anthropic security researchers validated each vulnerability and wrote patches by hand; external researchers were added as volume grew.Section 'Setup'
Findings that cite this record
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
Sources
Related records
Feb 20, 2026
Mar 6, 2026
May 22, 2026
Oct 30, 2025
Apr 7, 2026
Oct 3, 2025