Mozilla Releases Firefox 150, Uses Claude Mythos AI to Fix 271 Vulnerabilities
The Mozilla Foundation used Anthropic’s Claude Mythos AI in Firefox 150 to help analyze vulnerabilities, showing that generative AI is expanding from content creation into cybersecurity defense. Mozilla says the model can assess threats at a level approaching that of cybersecurity experts, shortening the time needed for manual code reviews and vulnerability discovery while making browser security maintenance more efficient.
When Mozilla released Firefox 150, it said it had fixed 271 security vulnerabilities identified by Claude Mythos. Subsequent disclosures showed that 423 Firefox vulnerabilities had recently been addressed with AI assistance, 152 more than initially announced. The development drew attention in a May 11 cybersecurity report and highlighted the real-world scale of AI-assisted vulnerability discovery.
All Coverage
3 original reportsThe Backstory
The history behind this eventMozilla Adds AI Chat to Firefox 155, Fixes 29 Security Flaws
Mozilla Foundation is expanding Firefox’s role beyond conventional web browsing by testing Smart Window, an AI chat feature designed for interaction within the browser. The move places Mozilla in the industry-wide contest to make generative AI a core browsing interface, while raising the stakes around privacy and user control. Firefox 155 also strengthens visibility into online tracking and gives users more flexibility in organizing isolated browsing environments.
Firefox 155 makes Smart Window available on a trial basis in selected countries, with broader availability not yet specified. The release adds a tracker count display and a sorting mechanism for containers, helping users monitor tracking activity and manage separated browsing sessions. Mozilla also addressed 29 security vulnerabilities in the update, including several dangerous flaws assessed as critical by the U.S. Cybersecurity and Infrastructure Security Agency, or CISA.
AI-Assisted Vulnerability Research Gains Traction as Mozilla and GitHub Report Surge in Disclosures
Zero-day vulnerabilities can be exploited before patches are available, and identifying them has traditionally depended heavily on security researchers reviewing code one case at a time. Anthropic’s Claude Mythos has now been incorporated into research workflows at developers including Mozilla and Microsoft, helping broaden the scope of detection and improve verification efficiency. The shift suggests vulnerability research is moving beyond individual expertise toward a scalable, open-source security framework.
Based on information provided as of July 20, 2026, AI-assisted vulnerability cases involving Mozilla, Microsoft and Curl have drawn attention. GitHub has also observed a significant increase in privately reported vulnerabilities and CVE applications. However, related reports do not disclose the total number of vulnerabilities, the growth rate, individual reporting dates or any associated monetary amounts. The focus at this stage is the systemic shift emerging in the vulnerability reporting ecosystem.
Anthropic, Mozilla Use Claude Opus 4.6 to Find 22 Firefox Flaws
Firefox is an open-source browser maintained by Mozilla and used by hundreds of millions of people daily, directly processing untrusted web content. Anthropic and Mozilla began working together in February 2026, using Claude Opus 4.6 to scan nearly 6,000 C++ files. The model found 22 security vulnerabilities in two weeks, including 14 classified as high severity, highlighting AI's potential to accelerate defensive security audits.
Anthropic disclosed on March 6, 2026, that most of the vulnerabilities had been patched in Firefox 148. The team also spent roughly $4,000 in API credits on hundreds of tests, but succeeded only twice in generating exploits for use in a test environment. Mozilla later announced on April 21 that 271 vulnerabilities identified by Claude Mythos Preview had been included in that week's Firefox 150 fixes.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →