Anthropic, Mozilla Use Claude Opus 4.6 to Find 22 Firefox Flaws
Firefox is an open-source browser maintained by Mozilla and used by hundreds of millions of people daily, directly processing untrusted web content. Anthropic and Mozilla began working together in February 2026, using Claude Opus 4.6 to scan nearly 6,000 C++ files. The model found 22 security vulnerabilities in two weeks, including 14 classified as high severity, highlighting AI's potential to accelerate defensive security audits.
Anthropic disclosed on March 6, 2026, that most of the vulnerabilities had been patched in Firefox 148. The team also spent roughly $4,000 in API credits on hundreds of tests, but succeeded only twice in generating exploits for use in a test environment. Mozilla later announced on April 21 that 271 vulnerabilities identified by Claude Mythos Preview had been included in that week's Firefox 150 fixes.
All Coverage
2 original reportsThe Backstory
The history behind this eventMozilla Releases Firefox 150, Uses Claude Mythos AI to Fix 271 Vulnerabilities
The Mozilla Foundation used Anthropic’s Claude Mythos AI in Firefox 150 to help analyze vulnerabilities, showing that generative AI is expanding from content creation into cybersecurity defense. Mozilla says the model can assess threats at a level approaching that of cybersecurity experts, shortening the time needed for manual code reviews and vulnerability discovery while making browser security maintenance more efficient.
When Mozilla released Firefox 150, it said it had fixed 271 security vulnerabilities identified by Claude Mythos. Subsequent disclosures showed that 423 Firefox vulnerabilities had recently been addressed with AI assistance, 152 more than initially announced. The development drew attention in a May 11 cybersecurity report and highlighted the real-world scale of AI-assisted vulnerability discovery.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.