Chronicle/Defense & research

Google says Big Sleep found SQLite CVE-2025-6965 before attackers could exploit it

DefenseVulnerability disclosureSignificance assistant-drafted

Google reports that, working from Google Threat Intelligence information, the Big Sleep agent found a critical SQLite memory-corruption flaw (CVE-2025-6965) that Google says was known only to threat actors and at risk of exploitation. Google says it reported the flaw for patching before attackers could exploit it, says it believes this is the first time an AI agent directly foiled an in-the-wild exploitation effort, and says Big Sleep is being applied to open-source projects.

Why it matters

Google describes it as an AI agent directly foiling a planned exploitation; if accurate, it shows defensive agents being used operationally, not only in research.

Key facts

As stated in the sources, with where to find them.

  • Big Sleep discovered CVE-2025-6965 in SQLite based on intel from Google Threat Intelligence; Google describes it as critical and known only to threat actors.Section '1. Giving defenders an edge with agentic capabilities'
  • Google believes this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.Same section
  • Sandra Joyce (VP, Google Threat Intelligence) says GTIG threat intelligence and Big Sleep together identified the flaw, which Google reported for patching before the attackers could exploit it.Cloud CISO Perspectives, Sandra Joyce

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records