YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0057

Register entry

SQLite stack buffer underflow in seriesBestIndex, the first public Big Sleep find, fixed before release

Project
SQLite
Component
seriesBestIndex
Finder
Google Big Sleep
Autonomy
agent finds and reproduces; a human expert reviews before reporting
Evidence tier
Claim outside the record
Bounty
None published
Confidence
CONFIRMED

What happened

Google reported a write into a stack buffer with a negative index when a query carried a constraint on the rowid column; the project fixed it the same day and it never shipped. Google calls it "the first public example of an AI agent finding a previously unknown exploitable memory-safety issue in widely used real-world software".

Credit as recorded: no CVE: the project fixed it the same day, before release. Date basis: Project Zero announcement, 1 November 2024.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026