CyberKimi AI Claims It Weaponized a Chrome V8 Patch in Under a Day
CyberKimi, an unrestricted fork of Moonshot’s Kimi K3, is claimed to have turned a Chrome V8 security patch published on 2 September 2026 into a working sandbox-escape exploit in under 24 hours. Nobody has reproduced it, the demonstration video runs with the sandbox disabled, and the target build predates shipping Chrome Stable. This is a working read of the claimed exploit chain, the four things the evidence does not establish, Google’s separate and confirmed CVE-2026-85046 zero-day, the vendor’s published ExploitBench and CyberGym numbers, and the gap between those benchmarks and this claim.