What it is
Big Sleep is an AI-assisted vulnerability research agent developed by Google DeepMind and Google Project Zero. It evolved from Project Naptime, a research framework built to evaluate offensive security capabilities of large language models in workflows that resemble human vulnerability research.
The public record begins with the November 2024 Project Zero write-up of an exploitable SQLite stack buffer underflow found before release. It now expands to 21 public CVEs across SQLite, Chrome V8 and ANGLE, and Apple WebKit.
What is verified
The strongest entries are direct upstream credits: Chrome release notes and Apple security advisories that name Google Big Sleep, plus Google and Project Zero posts describing SQLite findings.
Chrome’s August-November 2025 releases directly add eleven previously omitted Big Sleep credits. This profile still excludes private findings, unpublished issue-tracker entries, and rumors.
Why it matters
Big Sleep is the best-documented case that AI-assisted vulnerability discovery has moved from benchmark performance into accepted product-security workflows. It is also a useful counterweight to hype: the strongest results pair model reasoning with source access, tooling, variant-analysis framing, threat intelligence, and human disclosure discipline.