Full Breakdown
AI Agents Trigger Record FFmpeg and Chrome Vulnerabilities
6/8/2026, 12:17:02 AM
Core Event
In early June 2026, security startup depthfirst reported that its autonomous AI agent discovered 21 zero-day bugs in FFmpeg, assigning CVE-2026-39210-CVE-2026-39218 to nine. The same week Google shipped Chrome 149, patching a record 429 vulnerabilities—including 22 critical and 87 high-severity flaws such as CVE-2026-10881 (CVSS 9.6). Only the FFmpeg bugs were directly AI-found, but the Chrome release follows a bounty-program overhaul driven by a flood of AI-generated reports.
Background & Context
AI tools—depthfirst’s scanner, Google’s Big Sleep, and Anthropic’s Mythos—are generating large volumes of vulnerability reports. A February study found an AI agent reproducing proofs-of-concept for over half of 100 real Linux-kernel N-day bugs, surpassing fuzzing. Consequently, Google overhauled its bug-bounty program in April, now demanding concise reproducible proofs to handle the AI-driven influx.
Key Figures & Groups
Key participants include depthfirst, the security startup behind the autonomous FFmpeg scanner; Google, which manages Chrome development and the bounty program; Google’s Big Sleep AI tool that previously reported FFmpeg bugs; Anthropic’s Mythos model that uncovered a 16-year-old H.264 flaw; and volunteer triagers who validate reports.
Data & Statistics
FFmpeg: 21 zero-days found; nine CVEs (CVE-2026-39210-CVE-2026-39218) assigned; some bugs date back 15–23 years; AI run cost ? $1,000. Chrome 149: 429 bugs patched (22 critical, 87 high, 226 medium, 94 low), including 110 use-after-free and 88 input-validation flaws; critical CVE-2026-10881 (out-of-bounds read/write) earned $97,000. Total Chrome bounty payouts reached $209,000.
Official Statements & Responses
Google’s revised bounty policy now requires concise reproducible exploits, reflecting the surge of AI-generated submissions. The firm paid $97,000 for CVE-2026-10881 and $209,000 in total for Chrome 149. depthfirst said its AI agent scanned about 1.5 million C lines in FFmpeg and produced reproducible PoCs for each bug. Google urges users to upgrade immediately to Chrome 149.0.7827.53/54 on all platforms.
Criticism & Opposition
The rapid influx of AI-found bugs has lowered discovery costs, but triage, fix deployment, and installation remain resource-intensive, relying heavily on volunteers and a thin layer of human triagers who must keep pace with machines. This pace strains patch-management, prompting calls for shorter release cycles and treating dependency updates as security work.
Conflicting Reports & Gaps
depthfirst notes nine FFmpeg CVEs are publicly assigned, while the other 12 are fixed but not yet numbered, creating a tracking gap. Google has not directly linked any of the 429 Chrome bugs to AI findings, despite the bounty overhaul. No evidence of wild exploitation exists for either project, though monitoring continues.
What’s Next
Google intends to further refine its bounty program for the growing AI-generated submission flow. Security teams are urged to enable auto-updates, shorten patch cycles, and allocate triage resources. Research indicates AI agents will keep accelerating vulnerability discovery, making timely patch deployment a critical defensive priority for organizations worldwide.
