A security startup, depthfirst, reports that an autonomous AI agent uncovered 21 previously unknown vulnerabilities in FFmpeg, the widely used open-source media library that powers video and audio processing across many products. The startup says the testing run cost about $1,000 in compute and that some of the issues had remained undiscovered in FFmpeg’s codebase for more than 20 years. The findings are presented as FFmpeg zero-days because they were not previously disclosed.
In a separate but related timeframe, Google releases Chrome 149 with security fixes for 429 bugs. The company describes this as a record number of patches for a single Chrome release. The sources note that the AI agent’s contribution is specific to the FFmpeg vulnerabilities, while the Chrome update addresses vulnerabilities found through Google’s established security processes rather than by the AI system described in the FFmpeg report.
Together, the reports highlight simultaneous developments in software security: newly disclosed FFmpeg flaws identified with AI-assisted analysis and a large-scale Chrome update that applies many fixes at once.