All findings

CVE-2026-5398, CVE-2026-6386 high

FreeBSD April kernel follow-ups credited to Nicholas Carlini using Claude

FreeBSD-SA-26:10.tty and FreeBSD-SA-26:11.amd64 credit Nicholas Carlini using Claude, Anthropic for two additional kernel security advisories after CVE-2026-4747.

Bug class
Kernel use-after-free and memory-protection logic flaws
Affected codebase
FreeBSD kernel
Credited system
Claude / Anthropic Research
Disclosed
April 21, 2026
Attribution
Direct source attribution
Severity
high
Source status: The FreeBSD security advisories directly credit Nicholas Carlini using Claude, Anthropic. CVE-2026-5398 can let a malicious process grant itself root privileges; CVE-2026-6386 lets an unprivileged user overwrite memory outside intended permissions on affected amd64 systems.

Summary

On April 21, 2026, FreeBSD published two additional kernel security advisories credited to “Nicholas Carlini using Claude, Anthropic.”

Why this matters

CVE-2026-4747 is the headline FreeBSD case because Anthropic says Mythos Preview fully autonomously discovered and exploited it. These follow-up advisories matter for a different reason: the FreeBSD project’s own advisory stream now contains multiple direct “using Claude” credits in core kernel components.

Caveat

The public FreeBSD advisories do not name the exact Claude model or claim full autonomy. This entry therefore uses the generic Claude / Anthropic Research system profile rather than assigning the follow-ups to Mythos Preview.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.