CVE-2025-6965Active Exploitation(apple / ipados)

MEDIUMCVSS 7.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-197

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • ruggedcom_crossbow

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
ipadosiphone_osmacosruggedcom_crossbowsidis_primesqlitetvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-22: 1Mentions · 2026-07-29: 1Mentions · 2026-08-23: 1Mentions · 2026-09-15: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-08-23: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-04-22: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-23: 1Technical Details · 2026-09-15: 104-2207-2908-2309-15
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Active Exploitation1
2026-07-291
Disclosure1
2026-08-231
Active Exploitation1
2026-09-151
Disclosure1
Full discourse4 posts
  • HITCON@HacksInTaiwan
    Disclosure

    Last July, Google revealed a fascinating case that may change how we think about vulnerability disclosure. Big Sleep, an AI agent jointly developed by Google DeepMind and Project Zero, successfully discovered a memory corruption vulnerability in SQLite (CVE-2025-6965) and helped researchers report and patch it before attackers could weaponize it. What makes the case even more remarkable is how little information the research team had to begin with. They only knew one thing: someone might be preparing to exploit an unknown vulnerability in SQLite. But no one knew what the vulnerability was—or where it was hiding. Using this limited threat intelligence, Big Sleep analyzed the code, reasoned about potential locations, and ultimately identified the vulnerability, helping researchers validate the finding and complete the disclosure process. The case raises a bigger question: If AI can dramatically reduce the time it takes to find vulnerabilities, is it time to rethink a vulnerability disclosure system that has been in place for more than a decade? For years, the security community has relied on a shared framework: researchers privately notify vendors, give them time to fix the vulnerability, and only then disclose the details publicly. Project Zero’s 90-day disclosure policy is one of the most influential examples of this approach. But this system rests on an important assumption: Finding vulnerabilities is slow, difficult, and expensive. AI is rapidly changing that assumption. Big Sleep has shown that AI can use limited clues to reason its way toward the location of a vulnerability. And when publicly available information can itself become a clue for AI to identify new vulnerabilities, are today’s disclosure practices still appropriate for the AI era? Does the disclosure period still matter? And what information should be disclosed—and when? These are at the heart of James Forshaw’s HITCON Keynote, Vulnerability Disclosure in the Age of AI. 🌟 Vulnerability Disclosure in the Age of AI — James Forshaw 【🪧 About the Keynote】 Known for his research into Windows logic vulnerabilities and sandbox escapes, James Forshaw is also the creator of open-source security tools widely used by researchers across the industry. More importantly, he isn’t simply an outside commentator on vulnerability disclosure. He is a practitioner who has been part of Project Zero’s vulnerability disclosure policy in action. In this keynote, James will look back at the history of vulnerability disclosure, examine how AI is changing the assumptions behind today’s disclosure practices, and ask whether we need to rethink the social contract that has shaped the global security industry for years. If you care about vulnerability research, threat intelligence, AI Security, or how AI will reshape the pace of offense and defense, this is a keynote you won’t want to miss. Because this isn’t just a discussion about how AI finds vulnerabilities. It’s about what happens to vulnerability disclosure when AI changes how fast we can find them. And that may be the next turning point for the security industry. Ticket information and registration: https://hitcon.kktix.cc/events/hitcon-2026 #HITCON2026 #HITCON #HackerConference #CyberSecurity #AISecurity

    Post summary

    Big Sleep, a Google DeepMind AI agent, identified a memory‑corruption flaw (CVE‑2025‑6965) in SQLite and assisted researchers in patching it before it could be weaponized, prompting a discussion on whether traditional vulnerability disclosure timelines remain appropriate in an AI‑driven era.

    01052483
    3.1K followersView on X
  • francescofaenzi@francescofaenzi
    Disclosure

    ## **5 Key Metrics Defining the Current Landscape:** 1. **0 (Zero) Days:** The exploitation window for CVE-2025-6965 (a critical SQLite zero-day). Google's "Big Sleep" AI agent proactively discovered, flagged, and neutralized this flaw before malicious actors could weaponize it, marking a historic shift from reactive to proactive defense. 2. **12.1%:** The baseline vulnerability rate in AI-generated code across 7,700+ analyzed GitHub files. Conversely, 87.9% of AI-generated code is free of CWE-mapped vulnerabilities, debunking the mainstream myth that LLMs universally write catastrophic code. 3. **34.0%:** The maximum vulnerability patching success rate achieved by State-of-the-Art (SOTA) autonomous LLM code agents (e.g., SWE-agent, OpenHands) on the rigorous SEC-bench evaluation. This represents the current hard ceiling of automated remediation. 4. **18.0%:** The success rate of AI agents in automatically generating functional Proof-of-Concept (PoC) exploits for discovered vulnerabilities, proving that autonomous weaponization is viable but still trails human ingenuity. 5. **1,739 LOC:** The "Security Density" metric (Lines of Code per CWE) achieved by GitHub Copilot when generating Python code. This acts as a benchmark, highlighting that AI code quality is highly dependent on language and tool selection. "Security Density" is defined as the volume of Lines of Code (LOC) generated before a Common Weakness Enumeration (CWE) is identified via static analysis (CodeQL).

    Post summary

    The text announces the discovery of CVE-2025-6965, a critical SQLite zero-day, by Google's AI agent prior to any weaponization, and contextualizes it within broader metrics on AI code security and automated remediation capabilities.

    10000112
    766 followersView on X
  • Kyssta@kysstalol
    Active Exploitation

    Google's Big Sleep AI agent foiled an in-the-wild SQLite zero-day (CVE-2025-6965, CVSS 7.2). First time AI directly blocked an active exploit attempt. Patched June 2026. Source: https://www.securityweek.com/google-says-ai-agent-thwarted-exploitation-of-critical-vulnerability/

    Post summary

    AI intervention successfully blocked an active exploitation of CVE‑2025‑6965, a SQLite zero‑day, which was later patched in June 2026.

    00000121
    22 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-6965 in Siemens RUGGEDCOM CROSSBOW SAC to execute arbitrary code via memory corruption. The vulnerability enables privilege escalation and lateral movement across networked industrial systems. Runtime segmentation can help limit blast radius in compromised OT environments. #Vulnerability #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-111-08-cve-2025-6965

    Post summary

    CVE‑2025‑6965 is being actively exploited against Siemens RUGGEDCOM CROSSBOW SAC, enabling arbitrary code execution, privilege escalation, and lateral movement. No patch or mitigation is referenced in the statement.

    00000279
    1.9K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---
Appsiemensruggedcom_crossbow---
Appsiemenssidis_prime---
Appsqlitesqlite---

Explore more