Google Project Zero reported that its Big Sleep large language model identified a previously unknown vulnerability in SQLite, marking a real-world bug discovery during testing on widely used open-source software. The flaw affects SQLite 3.47.0 and was traced to the seriesBestIndex function, where improper handling of rowid-related parameters can allow an invalid negative iColumn value.
The bug causes a stack buffer underflow that can lead to out-of-bounds heap writes, creating conditions that may be exploitable for attacks. According to reporting cited by CSIRT.SK, the issue had not been caught by existing fuzzing tools, underscoring the significance of AI-assisted vulnerability research; defenders were advised to update SQLite to the latest available version.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that the newly disclosed SQLite vulnerability affects SQLite 3.47.0 and said the issue had been missed by fuzzing tools. Its notice recommended updating to the latest SQLite version.
Google Project Zero published a report describing how its Big Sleep large language model found a previously undiscovered vulnerability in SQLite while testing real-world open-source software. The flaw was characterized as a stack buffer underflow that can lead to out-of-bounds heap writes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.