Security researchers used Claude to discover two separate remote code execution (RCE) vulnerabilities — one in Vim and one in GNU Emacs — simply by opening a crafted file. The Vim bug was patched immediately (upgrade to v9.2.0272 recommended), while Emacs maintainers declined to fix theirs, attributing it to git. The researchers used simple natural-language prompts to guide Claude toward finding these 0-days, comparing the ease to SQL injection exploits in the early 2000s. They are launching 'MAD Bugs: Month of AI-Discovered Bugs' to publish more AI-uncovered vulnerabilities throughout April.

2m read timeFrom blog.calif.io
Post cover image
1K Impressions