Google Uses AI to Discover 20-Year-Old Software Bug – PCMag
Google recently used an AI program to help it discover a software bug thats persisted in an open-source software project for the past two decades.
The software bug is among 26 vulnerabilities Google recently identified with the help of a ChatGPT-like AI tool, the company said in a blog post on Wednesday.
Google discovered the vulnerabilities through an approach called "fuzz testing," which involves feeding a software program random data to see if itll crash and then diagnosing the problem. Last year, the companystartedan effort to use large language models to write the fuzz testing code, offloading the work from humans who previously had to conduct the fuzz testing manually.
Our approach was to use the coding abilities of an LLM to generate more fuzz targets, Googles Open Source Security Team wrote in Wednesdays blog post. LLMs turned out to be highly effective at emulating a typical developers entire workflow of writing, testing, and iterating on the fuzz target, as well as triaging the crashes found.
An example of how the LLM does fuzz testing. (Credit: Google)
Since then, Google has applied the AI tool for fuzz testing across 272 software projects, which led it to discover the 26 vulnerabilities, including a 20-year-old bug found in OpenSSL, which is widely used to provide encryption and server authentication for internet connections.
"We reported this vulnerability on September 16 and a fix was published on October 16. As far as we can tell, this vulnerability has likely been present for two decades and wouldnt have been discoverable with existing fuzz targets written by humans," researchers added.
The 20-year-old bug, dubbed CVE-2024-9143, involves the software triggering an "out-of-bounds memory access," which can cause the program to crash or, in rare cases, execute rogue computer code. Fortunately, the bug is low severity due to the minimal risk of the out-of-bounds memory access executing a dangerous process.
Still, Google theorizes the bug went undiscovered because the specific code was presumed to be thoroughly tested and vetted. Code coverage as a metric isnt able to measure all possible code paths and statesdifferent flags and configurations may trigger different behaviors, unearthing different bugs," researchers said. "These examples underscore the need to continue to generate new varieties of fuzz targets even for code that is already fuzzed."
Going forward, Google's Open Source Security Team is working to make the LLMs suggest a patch for any bugs found during the fuzzing process. Another goal is "to get to a point where we're confident about not requiring human review," the team said. "This will help automatically report new vulnerabilities to project maintainers."
The effort joins another Google AI project, dubbed "Big Sleep," which also involves finding security vulnerabilities by using LLMs to mimic the workflow of a human security researcher. Earlier this month, the company said Big Sleep was smart enough to discover a previously unknown and exploitable bug in SQLite, an open-source database engine.
Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
I've been working as a journalist for over 15 yearsI got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017.
Read Michael's full bio
Read more:
Google Uses AI to Discover 20-Year-Old Software Bug - PCMag
- 7 tell-tale signs of bed bugs to look out for in your home - and what ... - January 21st, 2025
- Save your stuff and your sanity: SC expert bed bug tips to know on your Myrtle Beach vacation - Myrtle Beach Sun News - January 21st, 2025
- My Apartment Has Bed Bugs. What Are My Rights as a Tenant? - January 21st, 2025
- This particular smell could signal you have bed bugs, experts warn - Daily Record - January 19th, 2025
- Dallas, Houston And Other Texas Cities Have A Nasty Roach Problem - etsn.fm - January 19th, 2025
- Seven warning signs of bed bugs in your home - and how to get rid of them - The Mirror US - January 19th, 2025
- Experts issue warning to Brits to look out for these key signs of bedbugs in homes - Manchester Evening News - January 19th, 2025
- How to Spot Bed Bugs: Key Indicators and When to Call for Help ... - January 16th, 2025
- Recognising bed bugs and preventing infestation - January 16th, 2025
- Cases of norovirus (stomach bug) skyrocket in US: What to ... - Fox News - January 16th, 2025
- Bug Fables: The Everlasting Sapling/Medals - StrategyWiki - January 16th, 2025
- Kid With the Bed Bugs is Over | Y100 | Elvis Duran - Y100 - January 16th, 2025
- Up close and personal with the stag beetle in A Real Bugs Life S2 - January 16th, 2025
- Tell-tale sign of bed bugs to look out for in your home - and what to do - The Mirror - January 16th, 2025
- New Yorks Hated Invasive Pest Could Be Living Longer - WRRV - January 16th, 2025
- Mt. Pleasant library closed to treat bedbugs - The Morning Sun - January 16th, 2025
- Bedbugs and cockroaches assert their presence in the provincial hospital of Santiago de Cuba - CiberCuba - January 16th, 2025
- The Ultimate Guide to Bugging Out When All Hell Breaks Loose - January 14th, 2025
- Wayne County school closed Tuesday for treatment of bed bugs - News10NBC - January 14th, 2025
- Womans Viral Video Highlights Why You Should Never Put Amazon Packages on Your Bed - Green Matters - January 14th, 2025
- Camden Hills Deals with Bed Bugs - Midcoast Villager - January 14th, 2025
- 'He is paranoid... he is really scared hes going to get them or pass them on' - Yahoo News UK - January 14th, 2025
- Cleaning expert explains why you should never make your bed in the morning - The Mirror - January 14th, 2025
- Vacationers claim in suit they were bitten by bed bugs in their Myrtle Beach hotel rooms - Yahoo! Voices - January 12th, 2025
- Vacationers claim in suit they were bitten by bed bugs in their Myrtle Beach hotel rooms - The Times and Democrat - January 12th, 2025
- Bed bugs at SHES prompting closure - Shoshone News Press - January 9th, 2025
- Vacationers claim in suit they were bitten by bed bugs in their Myrtle Beach hotel rooms - Myrtle Beach Sun News - January 9th, 2025
- Vacationers claim in suit they were bitten by bed bugs in their Myrtle Beach hotel rooms - AOL - January 9th, 2025
- What is the Life Cycle of a Bed Bug? | Ehrlich Pest Control - January 7th, 2025
- Bedbug Scares And Hawaii Travel: What You Should Know - Beat of Hawaii - January 7th, 2025
- Bedbugs on board, Real ID's in 2025, bad luck at Chicago O'Hare, and the best hiking destinations by month (Saturday Selection) - Frequent Miler - January 7th, 2025
- 'This is as bad as I've seen it': attorneys file class action against OHA over bed bugs - KMTV 3 News Now Omaha - January 7th, 2025
- Turkish Airlines Isn't Doing Anything About Its Bedbug Problem: Report - Jalopnik - January 7th, 2025
- After months of outcry, low-income tenants sue Omaha Housing Authority over bed bug infestation - Flatwater Free Press - January 7th, 2025
- Lawsuit filed against Omaha Housing Authority claims 'continuous, building-wide bedbug infestations' - Omaha World-Herald - January 7th, 2025
- Bed Bugs in This Flight Made Other Airlines Alert - M9 - January 7th, 2025
- Bed bug season is here. Here's how to keep them out of your home. - January 5th, 2025
- Where do bed bugs come from? How they get in and what to do about it. - January 5th, 2025
- Bed bugs in your hotel or Airbnb? Here's what to do right away - January 5th, 2025
- Passengers Say Turkish Airlines Flights Have Unwelcome Guests: Bedbugs - The New York Times - January 5th, 2025
- Bed bug season: How to know if you have bed bugs and how to prevent - January 5th, 2025
- How to check for bed bugs to avoid an infestation this spring - January 5th, 2025
- Bedbugs in NJ? What they look like, how to ID bites - Bergen Record - January 5th, 2025
- Destiny Udogie out for six weeks with hamstring injury, Tottenham squad ... - January 5th, 2025
- Why are bed bugs virtually unkillable? It might be genes - Cosmos - January 5th, 2025
- Fliers Complain of Bedbugs on Flights to, From Istanbul - Newser - January 5th, 2025
- Im obviously going to call the front: Woman spends $1,500 for 2 nights at the Bellagio in Las Vegas. Then she notices something odd on her bedding -... - January 5th, 2025
- Bedbugs are more common on planes than people like to admit, cleaning expert says - Fortune - January 5th, 2025
- Year In Review #3: Popular Destination In New York State Is Crawling With Bed Bugs - Hudson Valley Post - January 3rd, 2025
- Paatal Lok season 2 teaser: Jaideep Ahlawat warns us about the bugs creeping in from the underworld - Cinema Express - January 3rd, 2025
- Turkish Airlines Reacted To A Bedbug Issue In The Worst Way Possible - TheTravel - January 3rd, 2025
- New Bedbug Research Reveals Genetic Secret to Fighting Infestations - SciTechDaily - January 3rd, 2025
- New breed of nearly invincible bed bugs that are 20,000 times tougher to kill is discovered - The Mirror US - January 1st, 2025
- New strain of super-powered bed bugs are 20,000 times tougher to kill - Daily Express US - January 1st, 2025
- Why You Should Put Your Luggage in the Bathtub of Your Hotel Room? - Green Matters - December 29th, 2024
- Bed bugs and possible transmission of human pathogens: a systematic ... - December 28th, 2024
- Arizona man Charles Smith arrested for spraying bug killer pesticide on ... - December 28th, 2024
- Home Office spent thousands on sniffer dogs to help get rid of bedbug infestation - Evening Standard - December 26th, 2024
- Study Identifies Genetic Mutations That Make Bed Bugs Hard to Kill - Mentalfloss - December 24th, 2024
- How to Make a Homemade Bed Bug Killer Spray With Vinegar - December 22nd, 2024
- Sixty Years Ago, We Nearly Wiped Out Bed Bugs. Then, They Started Changing - December 22nd, 2024
- Norovirus: Symptoms, Prevention, and When to See a Doctor | NGPG - December 22nd, 2024
- Man arrested after posting video of himself spraying bug killer on ... - December 22nd, 2024
- How to get rid of bed bugs in apartment buildings - Rentokil - December 22nd, 2024
- Video shows man spraying bug spray on produce, chicken at AZ Walmart - December 22nd, 2024
- Bug Ego - Wikipedia - December 22nd, 2024
- DHHS Workers, Administration Disagree on Whether Bed Bugs Are Rampant - Midcoast Villager - December 22nd, 2024
- How to use cinnamon to get rid of household pests - Ideal Home - December 22nd, 2024
- Sixty Years Ago, We Nearly Wiped Out Bed Bugs. Then, They Started Changing - ZME Science - December 20th, 2024
- Bedbugs Are Stronger Than Ever and Scientists Just Found Out Why - VICE - December 20th, 2024
- Bed Bugs & Dirty Clothes - PCT Online - December 20th, 2024
- Biologists Discover What Makes Bed Bugs Uniquely Hard to Kill With Insecticides - Gizmodo - December 20th, 2024
- Bug Tech selects single mother as its free bed bug treatment recipient - KLBK | KAMC | EverythingLubbock.com - December 18th, 2024
- Bed Bugs | Backyard Farmer | Nebraska - byf.unl.edu - December 17th, 2024
- Hotel Worker Reveals the Telltale Sign of Bed Bugs in Your Hotel Room Mattress - Green Matters - December 17th, 2024
- She Tells Her Sister To Be Careful About Visiting Their Parents Bed Bug Infested House, But Her Sister Thinks Shes Just Being Paranoid - Twisted... - December 13th, 2024
- She Tells Her Sister To Be Careful About Visiting Their Parents Bed Bug Infested House, But Her Sister Thinks Shes Just Being Paranoid - Twisted... - December 13th, 2024
- Sacrifice and Survival - PCT Online - December 13th, 2024
- Sacrifice and Survival - PCT Online - December 13th, 2024
- Do bed bugs have a favorite colour? - The Indian Express - December 13th, 2024