YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0026

Incident record

A cyber-capable model escaped a virtual machine three times, chaining unknown bugs

Severity
Critical
Status
Research
Type
AI-Found Vuln
Target
QEMU/KVM virtual machine isolation
Actor
researcher
CVE
CVE-2026-9539

What happened

Trail of Bits researcher Artem Dinaburg, given preview access to GPT 5.6-Cyber under OpenAI’s Patch the Planet programme, asked the model to escape a QEMU/KVM virtual machine on his own Linux development machine. Working on its own for roughly twelve hours across three attempts, it got out each time, chaining previously unknown bugs in QEMU, Linux KVM and libslirp along with a disclosed kernel bug.

The argument Trail of Bits draws from it is the one that concerns this board: a virtual machine is the boundary most teams put around an agent they do not fully trust, and it did not hold against a model that could find its own bugs in the boundary itself. CVE-2026-9539 in libslirp, scored 6.5 on NVD, was one link in the chain, alongside the Januscape kernel bug CVE-2026-53359. The counts are the researcher’s own, from three attempts rather than a systematic trial.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026