Briefing

Mozilla Uses Anthropic’s Claude Mythos to Patch 271 Firefox Vulnerabilities

security
by Bruce Schneier · Claude Anthropic

Patch to Firefox 150, examine the 271 vulnerability fixes, and update your security tooling to detect similar AI‑generated vulnerabilities.

What to do now

Patch to Firefox 150, examine the 271 vulnerability fixes, and update your security tooling to detect similar AI‑generated vulnerabilities.

Summary

Mozilla’s security team has leveraged Anthropic’s Claude Mythos AI model, part of the Project Glasswing initiative, to identify and remediate a record number of security bugs in the Firefox browser. In April 2026 alone, the team fixed 423 bugs—an unprecedented jump from the 20‑30 fixes per month seen in 2025—using a custom harness that guides Mythos through targeted tasks such as file I/O, test execution, and crash detection. The harness repeatedly runs until a sanitizer crash or other failure is observed, and a second language model grades the first model’s output to reduce hallucinations, resulting in almost no false positives.

During a two‑month scan, Mythos uncovered 271 vulnerabilities, of which 180 were classified as security‑high, 80 as security‑moderate, and 11 as security‑low. All were memory‑safety issues triggered by crafted HTML or code, including a 20‑year‑old XSLT flaw and a 15‑year‑old bug in the <legend> element. The AI‑generated test cases were fed into Mozilla’s fuzzing infrastructure for rapid triage, and the fixes were integrated into the 150 release, which saw 271 previously unknown bugs patched across subsystems such as JIT optimization, IPC race conditions, and sandbox escape vectors. The patching effort involved over 100 contributors who coordinated across builds 149.0.2, 150.0.1, and 150.0.2, and introduced prototype‑freezing hardening to block prototype‑pollution escapes.

The initiative demonstrates how generative AI can accelerate vulnerability detection in large, complex codebases. By embedding Mythos into the development pipeline, Mozilla has shown that AI‑driven scanning can surface legacy bugs before they become critical, offering a roadmap for other open‑source projects to adopt similar security research pipelines.

Key changes

  • Mozilla used Opus 4.6 to fix 22 bugs in Firefox 148.
  • With Mythos Preview, Firefox 150 fixed 271 vulnerabilities.
  • The collaboration demonstrates AI accelerating vulnerability discovery.
  • Mozilla scanned the codebase with AI agents that generate exploit code.
  • The release signals integration of AI tools into the security development lifecycle.

Affects

none

Source angles · 5 perspectives

Schneier on Security
Independent angle

Claude Mythos Has Found 271 Zero-Days in Firefox

Open
The Hacker News
Independent angle

Anthropic Releases Claude Mythos Model and Project Glasswing for Vulnerability Detection

Open
Simon Willison
Independent angle

Mozilla Uses Claude Mythos to Fix 423 Firefox Security Bugs in a Single Month

Open
Hacker News (front page)
Independent angle

Mozilla Demonstrates AI‑Assisted Vulnerability Detection with Anthropic Mythos

Open
Hacker News (front page)
Independent angle

Firefox Unveils 271 AI‑Discovered Security Fixes in 150 Release

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting