Google's Big Sleep AI agent halts exploitation of a SQLite zero-day
Google said its Big Sleep AI agent, built by DeepMind and Project Zero, found and helped stop real-world exploitation of a SQLite vulnerability (CVE-2025-6965) before attackers could use it.
- Security & misuse
- Notable
Google said its Big Sleep AI agent, developed jointly by DeepMind and Google’s Project Zero security team, had identified a critical vulnerability in the SQLite database engine and helped stop it being exploited before attackers could use it. The company described the episode as “the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.”
The flaw, catalogued as CVE-2025-6965, was a memory-corruption bug affecting SQLite versions before 3.50.2. Google said the vulnerability was known only to threat actors and was at imminent risk of exploitation; combining Big Sleep’s discovery with intelligence from its threat-analysis teams, the company said it was able to patch the flaw before it was used. Google gave few operational details of how the prediction and interdiction were made, and the claim rests on Google’s own account rather than an independently reviewed incident report.
Big Sleep, first deployed in November 2024, is one of several large-language-model-based tools labs have built to search open-source code for exploitable bugs, following earlier results such as its discovery of a stack-buffer-underflow vulnerability in SQLite that year. The July episode was notable less for the discovery itself, which the tool had already demonstrated it could do, than for the claim that an AI system had moved from finding vulnerabilities to acting in time to prevent their use — a step Google presented as evidence that automated defence could keep pace with automated offence, an argument likely to be tested repeatedly as such agents are adopted more widely on both sides of the security industry.