HN
Mad Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell
To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.
2026-03-26: FreeBSD published an advisory for CVE-2026-4747, crediting “Nicholas Carlini using Claude, Anthropic” for a remote kernel code execution.
9:45AM PDT 2026-03-29: We asked Claude to develop an exploit.
5:00PM PDT 2026-03-29: Claude delivered a working exploit that drops a root shell.
Total time: ~8 hours wall clock. The human was AFK for much of it; Claude’s actual working time was ~4 hours.
Claude actually wrote two exploits using two different strategies. Both worked on the first try. Here’s what it looks like:
By dnqthao