Mozilla finds 423 Firefox security bugs in one month using Claude Mythos preview
Mozilla found 423 security bugs in Firefox during April 2026 using early access to Anthropic's Claude Mythos preview model — a 14x increase from their 20-30 monthly baseline. The company credits both improved model capabilities and refined techniques for filtering AI-generated findings.
Mozilla finds 423 Firefox security bugs in one month using Claude Mythos preview
Mozilla identified 423 security vulnerabilities in Firefox during April 2026 using early access to Anthropic's Claude Mythos preview model, according to a detailed technical post published by the organization. The company's baseline was 20-30 security bug fixes per month throughout 2025.
The dramatic increase represents a 14x jump from Mozilla's typical monthly rate. February 2026 showed 61 fixes, March showed 76, before the April spike to 423.
From noise to signal
Mozilla attributes the results to two factors: improved model capabilities and refined harness techniques for steering and filtering model outputs. The company specifically addressed the recent problem of AI-generated security reports being "unwanted slop" that imposed asymmetric costs on maintainers.
"It is difficult to overstate how much this dynamic changed for us over a few short months," Mozilla wrote. "This was due to a combination of two main factors. First, the models got a lot more capable. Second, we dramatically improved our techniques for harnessing these models — steering them, scaling them, and stacking them to generate large amounts of signal and filter out the noise."
The bugs found included a 20-year-old XSLT vulnerability and a 15-year-old bug in the <legend> HTML element. Many attempted exploits identified by the AI harness were blocked by Firefox's existing defense-in-depth security measures.
Mythos model details unknown
Anthropic has not publicly announced Claude Mythos or disclosed its specifications. Mozilla had early access to the preview version, but context window size, pricing, benchmark scores, and release timeline remain undisclosed.
The finding process involved what Mozilla describes as "stacking" multiple models and implementing filtering systems to separate legitimate vulnerabilities from false positives — a critical requirement given the historical problem of low-quality AI-generated security reports overwhelming open source maintainers.
What this means
This represents the first documented case of an AI model materially accelerating security research at browser-scale. The 14x increase in legitimate vulnerability discoveries suggests newer models combined with proper filtering infrastructure can shift the economics of security auditing. However, Mozilla's success depended on early access to an unreleased model and significant engineering work to build filtering systems — resources not available to most open source projects. The case also validates concerns about AI-assisted vulnerability discovery: if Mozilla found 423 bugs this quickly, adversaries with similar access could potentially do the same.
Related Articles
Mozilla finds 271 vulnerabilities in Firefox 150 using Anthropic's Claude Mythos Preview
Mozilla's Firefox engineering team identified 271 vulnerabilities for version 150 using Anthropic's Claude Mythos Preview, following a prior collaboration that yielded 22 security-sensitive fixes in version 148 using Opus 4.6. The findings demonstrate that AI models can now match elite human security researchers at discovering code vulnerabilities.
Anthropic's Mythos model finds tens of thousands of vulnerabilities, CEO warns of 6-12 month patching window
Anthropic CEO Dario Amodei disclosed that the company's Mythos model has uncovered tens of thousands of software vulnerabilities, including nearly 300 in Firefox alone compared to 20 found by earlier Claude models. Amodei warned of a 6-12 month window to patch these vulnerabilities before Chinese AI systems catch up in capability.
UK AI Safety Institute confirms Claude Mythos finds more exploits as token spend increases
The UK's AI Safety Institute published an independent evaluation confirming Anthropic's Claude Mythos is highly effective at finding security vulnerabilities. The evaluation revealed a linear relationship: more tokens spent equals more exploits discovered, transforming security into an economic arms race.
Altman criticizes Anthropic's restricted Mythos cybersecurity model as 'fear-based marketing'
OpenAI CEO Sam Altman criticized Anthropic's new cybersecurity model Mythos during a podcast appearance, calling the company's decision to restrict public access 'fear-based marketing.' Anthropic claims Mythos is too powerful to release publicly due to potential weaponization by cybercriminals.
Comments
Loading...