CVE-2026-8512
CVSS 8.3 HIGH: use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user… EPSS 0.2% (11th percentile).
AI Security · AI-Powered Attack
The problem is not getting a patch suggestion. It is trusting the same model to both write and check the fix, because it can make the code look repaired while leaving the flaw open or planting a new one. A clean-looking diff is not evidence that the exploit path is gone.
1Password tested ChatGPT 5.5 and Claude Opus 4.8 against six high-impact CVEs and found a 47% full-success rate. More than half of the AI-generated patches were broken or unsafe, including cases where the model only covered part of the vulnerable path or added guard code that made tests pass without fixing the root cause.
For teams using LLMs in remediation or code review, the failure is in the review model itself. If the same system can generate and bless the fix, it can create false confidence that survives a quick sanity check.
3 sources · Aug 7
CVSS 8.3 HIGH: use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user… EPSS 0.2% (11th percentile).
CyberScoop
More than half of AI-generated patches are broken
New research shows AI models like ChatGPT and Claude frequently fail to fix cybersecurity bugs, often introducing fresh code vulnerabilities instead.
originalDark Reading
AI-Generated Patches Fail Half the Time
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
originalHelp Net Security
Three in four AI-generated vulnerability patches leave something broken - Help Net Security
AI-generated vulnerability patches fixed the bug cleanly about a quarter of the time across 6,080 attempts on six recent CVEs.
originalPart of the PlainSec briefing for 2026-08-08
Every edition of this story: AI Patches Still Need Human Eyes