HomeSecurityClaude Opus 4.6: Detected 500+ bugs in open-source libraries

Claude Opus 4.6: Found 500+ bugs in open-source libraries

Artificial intelligence (AI) company Anthropic has revealed that its latest large language model (LLM), Claude Opus 4.6, has identified more than 500 new security flaws in open source libraries, including Ghostscript, OpenSC and CGIF.

Claude Opus 4.6

Claude Opus 4.6, released Thursday, features skills programming, including code review and debugging. There have also been improvements to tasks such as financial analysis, research and document creation.

Anthropic Claude Opus 4.6: Effective in detecting vulnerabilities

The model is “significantly better” at discovering serious vulnerabilities without requiring a special toolkit, custom support, or specialized guidance. Anthropic uses it to identify and help fix vulnerabilities in open source software.

See also: Four new vulnerabilities in Ingress NGINX

“Opus 4.6 reads and analyzes code like a human researcher would — examining previous fixes to find similar bugs that were not addressed, identifying patterns that commonly cause problems, or understanding a piece of logic well enough to know exactly what input would break it,” the company said.

Before its release, Frontier Red tested the model in a virtualized environment and provided it with the necessary tools, such as debuggers and fuzzers, to find bugs in open source projects. The goal was to evaluate the model's ability, without providing it with instructions on how to use these tools or information that could help it better identify vulnerabilities.

Claude Opus 4.6: Found 500+ bugs in open-source libraries

The company validated each discovered bug to ensure it was not fabricated (i.e., an “illusion”) and that LLM was used as a tool to prioritize the most serious memory vulnerabilities identified.

See also: Attackers exploit old Windows vulnerability to disable EDR

The most important issues identified by the model

Some of the security bugs highlighted by Claude Opus 4.6 include:

– Analyzing Git's commit history to identify a vulnerability in Ghostscript that could lead to a crash due to a lack of bounds checking.

– Search function calls, such as strrchr() and strcat() to detect a buffer overflow vulnerability in OpenSC.

– A heap buffer overflow vulnerability in CGIF (fixed in version 0.5.1).

“This vulnerability is particularly interesting because its activation requires an understanding of the LZW algorithm and how it relates to the GIF file format,” Anthropic noted about the CGIF flaw. “Traditional fuzzers (and even guided coverage fuzzers) have difficulty activating vulnerabilities of this kind because they require a specific selection of branches.”

Claude Opus 4.6: Found 500+ bugs in open-source libraries

“In fact, even if CGIF had 100% line- and branch-coverage, this vulnerability could remain invisible: it requires a very specific sequence of operations.“.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

The company has positioned AI models like Claude as critical tools for network defenders, but it stressed that it will adapt and update its safeguards as potential threats are discovered and implement additional measures to prevent misuse.

This revelation comes just weeks after Anthropic stated that current Claude models can succeed in multi-stage attacks on networks with dozens of hosts, using only standard open source tools and exploiting known security flaws.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS