
Researchers just published a paper on an AI agent that found 10 zero-day vulnerabilities in Google Chrome. Including two critical sandbox escapes. CVE-2026-5280 and CVE-2026-6297. One malicious tab. Full system compromise. These weren't easy bugs. Human auditors missed them. Automated fuzzers missed them. For decades. The AI found them in a single research run. The system is called AgentFlow. It coordinates multiple AI agents - each with different roles, tools, and feedback loops - optimizing the harness automatically until something breaks. The implications aren't theoretical. Every piece of critical software written before AI security auditing existed was reviewed by humans and fuzzers that are now provably less capable than what's available today. The question isn't whether AI can find vulnerabilities. It already has. The question is who finds the next ones first.
Post summary
A research paper reports that an AI-driven system (AgentFlow) uncovered 10 zero‑day vulnerabilities in Google Chrome, including two critical sandbox escapes leading to full system compromise, underscoring AI’s growing capability to find previously missed bugs.


