AI Agent Discovers 21 Zero-Day Vulnerabilities in FFmpeg; Chrome Patches Record 429 Bugs
A security startup has reported the discovery of 21 previously unknown vulnerabilities in FFmpeg, a widely used media library, by an autonomous AI agent. These vulnerabilities, known as zero-days, were found in the project's 1.5 million lines of C code, with some dating back as far as 2003. The AI agent, developed by depthfirst, identified these vulnerabilities at a cost of approximately $1,000. In parallel, Google has released Chrome 149, which includes patches for 429 security bugs, marking the highest number of fixes in a single release. This surge in vulnerability discovery is attributed to AI's ability to rapidly identify and report security issues, prompting Google to overhaul its bounty program to manage the influx of AI-generated reports.