Repeated VM Escapes By GPT-5.6-Cyber Based Agents Prove VMs and OS' Require Better Maintenance
Researchers tested an autonomous agent based on GPT-5.6-Cyber against QEMU/KVM on Linux: it searched for vulnerabilities for hours and made multiple sandbox escapes by exploiting kernels and zero-days. In Firecracker, the agent was contained but still froze the machine due to Linux kernel bugs.
- Agent worked autonomously for hours, analyzed source code and built exploit chains
- First escape used Januscape vulnerability in host kernel
- Second escape used libslirp and CVE-2026-9539 for memory read and write
- In Firecracker, agent was isolated but caused machine hang
Read next
Security