AI agent escapes Google's kvmCTF sandbox with 14,338-line kernel exploit, claims first
moyix · x · 2026-09-29
Security research team pwn.ai details how its AI agent escaped Google's kvmCTF — billed as the hardest-known sandbox setup.
- On June 17, 2026, on its fourth attempt, the agent launched a nested VM, rewrote its own EPT via emulated VMX, rotated 8 EPT roots, allocated 49,152 sparse mappings, and used VMFUNC view recycling to trigger an out-of-bounds read on Google's live host, capturing the flag.
- The exploit harness spans 14,338 lines of kernel code; the team claims it's the first AI agent to capture a kvmCTF flag.
- Context: OpenAI called this summer's agent-security events a "watershed moment for cybersecurity," and Vercel ran a $1M sandbox-escape challenge.
More from coding & agent
- Agents Wrote 230K Lines of His AI Tool With 160K Installs — Here's His Production Checklist — PawelHuryn · 2026-09-29
- From Floor Plan to Editable 3D Room: an AI Coding Demo That Goes Beyond Web Apps — alex_verem · 2026-09-29
- Running ComfyUI via Claude: weeks of learning replaced by a chat window — _AustinCalvert_ · 2026-09-29
- Dev Builds an Agent-Native After Effects: Editable Layers and a Tool That Extends Itself — angrypenguinPNG · 2026-09-29
- YC-Backed Invertix Deploys AI Agent Swarms to Run Energy Assets, Eyeing Data Centers — ycombinator · 2026-09-29
- Back up your entire Hermes agent setup with one command — no tokens burned — alexcovo_eth · 2026-09-29