XBOW's AI agent finds and exploits a Linux kernel 0-day, achieving local root privilege escalation
moyix · x · 2026-09-30
Security firm XBOW says its AI agent uncovered a Linux kernel vulnerability that human researchers had largely missed and developed it into a working LPE exploit.
- CVE-2026-72018: an out-of-bounds write in the Linux kernel
- Triggerable by an unprivileged user with CAPNETADMIN network admin capabilities
- Yields local privilege escalation to root (uid=0); the thread shows the exploit landing a root shell
- Author moyix frames it as the start of a series exploring whether agents can find and exploit kernel bugs, and where their autonomy breaks down
A landmark case of AI agents doing real-world vulnerability research and exploit development.
More from coding & agent
- Procedural cheetah in Three.js: GPT 6.1 Sol Max vs Opus 5.5 Max — majidmanzarpour · 2026-09-30
- Freebuff MCP: an open-source bridge letting Claude Code and Codex drive Freebuff via MCP — Swimming_Ask3859 · 2026-09-30
- Supply chain agent recalls a 3-week-old contract via Hindsight memory and refuses an order cancel — peggyraj · 2026-09-30
- Codex desktop Linux hang bug fixed in latest 26.928.20755 release — cedric_chee · 2026-09-30
- Hands-On Comparison of Top Gen AI Frameworks for Go in 2026: Genkit, Eino, ADK Go and More — rseroter · 2026-09-30
- mitsuhiko: use any llama.cpp model with Pi as a discount classifier — mitsuhiko · 2026-09-30