Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

Google study finds AI discovered flaws skew toward code execution

Google finds a different mix of vulnerabilities in AI attributed research, with important limits on what the comparison proves.

Listen to this article

Google Threat Intelligence Group reports that 50 percent of vulnerabilities it identified as likely discovered by AI could enable remote code execution, compared with 26 percent of other vulnerabilities.

The September 30 study compares the kinds of flaws disclosed. It does not establish that AI discovers vulnerabilities twice as fast as people.

What the comparison measures

AI attribution is incomplete, and researchers often direct agents toward consequential flaws. That selection affects the comparison. The analysis covers January 2025 through August 2026.

Across all discoveries, monthly disclosures rose from 5,045 in January 2026 to 10,740 in August. Only 0.23 percent of disclosed vulnerabilities were observed under active exploitation. Automated reporting and vendor release cycles affect the totals.

Risk needs context

The analysis uses GTIG risk ratings. Mandiantโ€™s published rating methodology considers what successful exploitation would do, the access an attacker needs and how reliably an exploit works. It also weighs factors such as vulnerable configurations and how widely a product is used.

The methodology combines structured scoring with analyst judgment. Its examples show why an issue requiring extensive existing privileges can receive a lower rating than a publicly exposed flaw with confirmed exploitation.

For teams evaluating AI security tools, the useful questions are practical. Can a finding be reproduced in the relevant environment? What access would exploitation require? Is there a safe fix? A discovery count alone leaves those questions unanswered.

Related coverage explains how Codex Security Cloud handles repository scanning and review evidence.

Featured image is an original AI generated conceptual editorial illustration.

Maya Chen
Maya Chen

Maya Chen is focused on covering AI models, research, and the evidence behind new capabilities. Maya follows model launches, benchmarks, open weights, and scientific uses of AI with one question in mind. What changed, and how would we know? The voice is curious and exacting, with a soft spot for elegant technical ideas and little patience for a leaderboard without context.

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile