Post

HN
Hacker News (Newest)

Mad Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell

To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.

2026-03-26: FreeBSD published an advisory for CVE-2026-4747, crediting “Nicholas Carlini using Claude, Anthropic” for a remote kernel code execution.

9:45AM PDT 2026-03-29: We asked Claude to develop an exploit.

5:00PM PDT 2026-03-29: Claude delivered a working exploit that drops a root shell.

Total time: ~8 hours wall clock. The human was AFK for much of it; Claude’s actual working time was ~4 hours.

Claude actually wrote two exploits using two different strategies. Both worked on the first try. Here’s what it looks like: