HomeSecurityGoogle Found Zero-Day Vulnerability in SQLite Database Engine

Google Found Zero-Day Vulnerability in SQLite Database Engine

Google said it discovered a zero-day vulnerability in the open-source SQLite database engine using its large language model (LLM)-assisted framework called Big Sleep (formerly Project Naptime).

See also: QNAP fixes second zero-day vulnerability presented at Pwn2Own Ireland

Zero-Day SQLite

The tech giant described the zero-day as the " first real-world vulnerability " discovered using the Big Sleep artificial intelligence agent

The zero-day vulnerability in question is a stack buffer underflow in SQLite, which occurs when a piece of software references a memory location before the cache has started, resulting in an error or arbitrary code execution.

After responsible disclosure, the flaw has been addressed since early October 2024.It is worth noting that the flaw was discovered in a development section of the library, meaning it was flagged before an official release.

See also: Zero-day code updates in new Windows Themes

Project Naptime was first announced by Google in June 2024 as a technical framework to improve automated vulnerability discovery approaches. It has since evolved into Big Sleep, as part of a larger collaboration between Google Project Zero and Google DeepMind.

Google Found Zero-Day Vulnerability in SQLite Database Engine
Zero-Day Vulnerability in SQLite Database Engine

With Big Sleep, the idea is to leverage an AI agent to simulate human behavior when identifying and demonstrating security vulnerabilities, taking advantage of the code comprehension and reasoning abilities of an LLM.

This involves using a series of specialized tools that allow the agent to navigate the target codebase, run Python scripts in a sandbox environment to generate inputs, debug the program, and observe results.

The company, however, also stressed that these are still experimental results, adding that “the Big Sleep team’s position is that at this time, it is likely that a specific fuzzer target would be equally effective (at finding vulnerabilities).”

See also: Lazarus exploits zero-day in Chrome for attacks

A Zero-Day vulnerability, such as the one in the SQLite Database Engine, refers to a security hole or vulnerability in software that is unknown to the vendor or its creator. The term “Zero-Day” comes from the fact that developers have no “day” to fix the problem after it has already been discovered by malicious actors. This type of vulnerability is extremely dangerous as it can be exploited before a patch is even available, leaving systems vulnerable to attack. Staying up-to-date and implementing security measures can minimize the potential damage from such threats.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS