Google's vice president of security announced that Big Sleep had reported 20 vulnerabilities, mostly in open-source projects such as FFmpeg and ImageMagick, with details withheld pending fixes. A Google spokesperson told TechCrunch each flaw was found and reproduced by the agent without human intervention, with a human expert reviewing reports before submission.
Why it matters
It documents a human-in-the-loop reporting model for AI-found bugs at a time when maintainers were complaining about low-quality AI reports.
Key facts
As stated in the sources, with where to find them.
- Big Sleep found and reported 20 flaws, mostly in open-source software such as FFmpeg and ImageMagick; issues are tracked on Google's issue tracker, with details withheld until fixes.TechCrunch article
- Google spokesperson Kimberly Samra said each vulnerability was found and reproduced by the agent, with a human expert in the loop before reporting.TechCrunch article
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
Sources
Related records
Jul 15, 2025
Nov 1, 2024
Sep 2, 2026
Aug 8, 2025
Oct 6, 2025
Sep 24, 2026