Vulnerabilities · 94 days ago

AI Bug Hunts Are Swamping Human Triage

The bottleneck is shifting from finding bugs to absorbing them. Cheap AI runs can now hand defenders a stack of reproducible flaws faster than teams can verify impact, sort priority, and ship fixes, and that pressure hits hardest in widely embedded code that sits inside other products.

This week brought both sides of that shift. A security startup said an autonomous agent found 21 confirmed FFmpeg zero-days with reproducible proofs of concept for about $1,000 a run, while Google shipped Chrome 149 with 429 security fixes, the most ever in one release, after overhauling its bounty program to handle a flood of AI-generated reports. The point is not the exact count; it is the growing gap between vulnerability throughput and human response capacity.

CVE-2026-10881

NVD KEV

CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Microsoft patch: Release Notes.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-06-07

Editions

Related stories