The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · pwn.ai · Google · KVM

pwn.ai team cracks Google's KVM hypervisor challenge

A pwn.ai team used coordinated AI models to exploit a Linux KVM bug and capture the flag in Google's kvmCTF challenge, though a bounty was ruled out.

A team at security group pwn.ai used a harness of coordinated AI models to exploit a use-after-free bug in Linux's KVM hypervisor, the group said. The exploit captured the flag in Google's kvmCTF challenge.

The team's models, drawn from OpenAI, Anthropic and DeepSeek, worked inside a human-supervised harness, pwn.ai said in a write-up published September 28. The harness grew from 3,304 lines of code to 14,338 lines in the version that succeeded. The exploit nested virtual machines three layers deep and created 49,152 sparse memory mappings to force KVM to dereference a stale pointer.

The bug, tracked as CVE-2026-46113, sat in KVM's shadow memory management unit in Linux 6.1.74. It had already been patched by the time pwn.ai reported it, and Google ruled the submission ineligible for a bounty because the fix and disclosure predated the report. The team captured the flag on its fourth attempt against Google's official host, after three earlier failures.

kvmCTF is Google's public bug-bounty program for the hypervisor that underlies Google Cloud and Android. The pwn.ai result adds to a run of reports this year of AI-assisted tools finding real vulnerabilities in production infrastructure. The team said the effort brought, in its own words, "only glory" rather than payment.

Sources 2 sources

  1. Source pwn.ai
  2. Source IntCyberDigest