AI Discovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Vulnerabilities

AI Discovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Vulnerabilities

First seen 6 Jun 2026, 13:55 UTC ThehackernewsThenextwebFeeds.4SysopsScworlddepthfirst.com+1 90% similarity 70.5

Article Content

Browse articles
ThreatCluster

An AI agent from the startup Depthfirst identified 21 zero-day vulnerabilities in FFmpeg, a widely used media library, with some flaws dating back over 20 years. These vulnerabilities include critical heap and stack overflows affecting various video processing applications. Concurrently, Google released Chrome 149, addressing a record 429 security bugs, with 22 classified as critical. The most severe bug, CVE-2026-10881, allows code execution outside Chrome's sandbox and scored 9.6 on the CVSS scale. The rapid discovery of vulnerabilities by AI tools highlights a growing challenge for security teams to manage the influx of reports. Depthfirst's AI agent achieved this at a cost of approximately $1,000, significantly lower than traditional methods. The situation indicates a shift in the cybersecurity landscape, where AI is outpacing human efforts in vulnerability discovery.

Key Points: • Depthfirst's AI agent found 21 zero-day vulnerabilities in FFmpeg, some over 20 years old. • Google's Chrome 149 patched a record 429 vulnerabilities, including 22 critical issues. • The rapid pace of AI-driven vulnerability discovery poses challenges for security teams.

ThreatCluster AI

Timeline

2026-06-04
CVE-2026-10881 published
CVE-2026-10881, a critical out-of-bounds read/write vulnerability in Chrome, was disclosed.
Thenextweb
2026-06-06
AI discovers 21 zero-days in FFmpeg
Depthfirst's AI agent uncovered 21 previously unknown vulnerabilities in FFmpeg, affecting video processing applications.
Thehackernews
2026-06-06
Chrome 149 released with 429 patches
Google released Chrome 149, fixing a record 429 vulnerabilities, emphasizing the need for improved bug triaging.
Feeds.4Sysops

Community

Browse all →