Skip to content
AI Model Exploits Outdated Chrome Version in Security Test

AI Model Exploits Outdated Chrome Version in Security Test

First seen 17 Apr 2026, 07:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 18, 2026 at 06:46 UTC
  • •Claude Opus exploited Chrome 138, demonstrating AI's potential in exploit development.
  • •The exploit targeted CVE-2026-5873, a remote code execution vulnerability in V8.
  • •Outdated software in Electron apps poses significant security risks as AI models advance.

A researcher used Anthropic's Claude Opus to exploit an outdated version of Chrome (138) bundled with Discord, demonstrating the potential for AI to automate exploit development. The exploit was built using known vulnerabilities in the V8 engine, specifically targeting CVE-2026-5873, a remote code execution flaw published on April 8, 2026. The researcher spent approximately $2,283 in API costs and 20 hours guiding the model through the process, which involved handling 2.3 billion tokens. This incident highlights the risks associated with outdated software, particularly applications built on Electron that often lag in updates. The researcher warns that as AI models improve, the ability to create exploit chains will become more accessible, raising concerns about the security of systems running outdated code. The test underscores a significant gap in patching practices and the urgency for organizations to update their software. The implications are serious, as even script kiddies could potentially exploit these vulnerabilities with minimal investment in time and resources.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 173d ago How this analysis works

Timeline

2025-11-10
CVE-2025-12429 published
2026-03-12
CVE-2026-3910 published
2026-03-13
CVE-2026-3910 added to CISA KEV (active exploitation)
2026-04-08
CVE-2026-5873 published
2026-04-17
Researcher demonstrated exploit using Claude Opus

More articles in this cluster (8)

Following this threat?

Track CVE-2026-5873 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed