Anthropic research shows that frontier LLMs can autonomously generate exploits for publicly disclosed vulnerabilities (N-days). This accelerates threats during the patch gap, giving attackers a significant advantage.
Anthropic published research evaluating LLMs' ability to exploit N-day vulnerabilities. Claude Mythos Preview autonomously built 8 working code-execution exploits out of 18 Firefox security patches, and 8 full privilege escalation chains out of 21 Windows kernel patches (without source code).
N-day vulnerabilities are publicly known but unpatched on many systems, posing a threat during the patch gap. Traditionally, patch diffing was slow and specialized, but LLMs can now automate this process, significantly accelerating exploit development.
The increasing capability of LLMs raises the risk during the patch gap, forcing defenders to accelerate patch deployment. Even publicly available models can generate exploits, making the technology accessible to potential attackers.