Article Details
Scrape Timestamp (UTC): 2025-11-04 08:12:58.851
Source: https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
Original Article Text
Click to Toggle View
Google's AI 'Big Sleep' Finds 5 New Vulnerabilities in Apple's Safari WebKit. Google's artificial intelligence (AI)-powered cybersecurity agent called Big Sleep has been credited by Apple for discovering as many as five different security flaws in the WebKit component used in its Safari web browser that, if successfully exploited, could result in a browser crash or memory corruption. The list of vulnerabilities is as follows - Patches for the shortcomings have been released by Apple on Monday as part of iOS 26.1, iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, watchOS 26.1, visionOS 26.1, and Safari 26.1. The updates are available for the following devices and operating systems - Big Sleep, formerly called Project Naptime, is an AI agent launched by Google last year as part of a collaboration between DeepMind and Google Project Zero to enable automated vulnerability discovery. Earlier this year, Google said the large language model (LLM)-assisted framework identified a security flaw in SQLite (CVE-2025-6965, CVSS score: 7.2) that it said was at "risk of being exploited" by malicious actors. While none of the vulnerabilities listed in Monday's security bulletins have been flagged as exploited in the wild, it's always a good practice to keep devices updated to the latest version for optimal protection.
Daily Brief Summary
Google's AI-powered agent, Big Sleep, discovered five security vulnerabilities in Apple's Safari WebKit, potentially leading to browser crashes or memory corruption if exploited.
Apple has released patches addressing these vulnerabilities across multiple platforms, including iOS, macOS, and Safari, as part of their latest software updates.
Big Sleep, formerly known as Project Naptime, is a collaboration between DeepMind and Google Project Zero, aimed at automating vulnerability detection using AI technology.
The vulnerabilities have not been reported as exploited in the wild, but users are advised to update their devices to the latest versions to ensure security.
This discovery follows Big Sleep's earlier identification of a significant flaw in SQLite, demonstrating the AI's capability in enhancing cybersecurity measures.
The proactive identification and patching of these vulnerabilities reflect the growing importance of AI in cybersecurity defense strategies.
Companies are encouraged to adopt similar AI-driven approaches to bolster their security posture and mitigate potential threats effectively.