Project Zero's antivirus research (2016)
Google Project Zero researcher Tavis Ormandy found critical, remotely exploitable vulnerabilities in multiple antivirus products, including flawed parsers in Avast, Kaspersky, and others. One Avast bug let a remote attacker take over a machine just by visiting a webpage.
Vendors rushed emergency patches; several products were shown to be remotely exploitable.
The research established that antivirus software massively expands the attack surface it claims to protect.
Same vendor, same pattern: antivirus replaces the kernel's built-in defenses with its own privileged, buggy code.
