Last seen July 16, 2025

CVE-2025-6965 Security Incident affecting Google

Evidence indicates that Google is affected by a security issue. Reported affected versions include

Technical Severity
Medium severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that Google is affected by a security issue. Reported affected versions include

Why This Matters

Current evidence identifies a security issue involving Google, but does not yet support a more specific impact claim.

Recommended Action

Upgrade to fixed version 9d7c5df7f0e42528bf514b5231d58273bea47e40 where the affected package is present. Identify deployments of Google matching the evidenced affected versions: <= 2.1.11.

Exposure

Recommended Response
First Seen

Jul 16, 2025 05:30

Last Seen

Jul 16, 2025 05:30

Exploitation status: UNKNOWN

Affected versions: <= 2.1.11

Primary entities:

Google AI Agents CVE-2025-6965 SQLitePCLRaw.lib.e_sqlite3 SQLitePCLRaw.lib.e_sqlite3.android SQLitePCLRaw.lib.e_sqlite3.ios

Authoritative Intelligence

CVE CVE-2025-6965 Incident identifier
NVD CVSS 7.2 HIGH NVD
FIRST EPSS 0.749 99.5 pct
GHSA GHSA-2M69-GCR7-JV3Q GitHub advisory alias
CWE CWE-197 Weakness classification

Provider evidence: NVD, GitHub Advisory, OSV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Jul 16, 2025 05:30

    BugSkan first recorded this incident.

  • Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act - The Hacker News
    Jul 16, 2025 05:30

    thehackernews.com · Vulnerability

Sources

Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act - The Hacker News

thehackernews.com · Jul 16, 2025 05:30

Google's AI agent, Big Sleep, discovered CVE-2025-6965, a critical memory corruption vulnerability in SQLite affecting versions prior to 3.50.2. This integer overflow flaw could allow an attacker to achieve a read off the end of an array by injecting arbitrary SQL statements, and was identified proactively to prevent impending zero-day exploitation.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence