
Fair challenge — but Project Big Sleep did get a CVE (CVE-2024-9243), and Google published the write-up through Project Zero. The nuance is that it was found in a controlled research setting, not spotted exploiting targets in the wild. Still a first though. The gap between "lab proof of concept" and "weaponised at scale" is shrinking faster than most people are comfortable with. 👀
Post summary
Project Big Sleep’s CVE-2024-9243 was disclosed by Google’s Project Zero with a lab proof of concept, but no evidence of real‑world exploitation has been reported.
