Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Claude Mythos Finds 271 Firefox Vulnerabilities

All the flaws could have also been found by an elite human researcher, according to Mozilla.

Firefox security

Mozilla says Anthropic’s new cybersecurity-focused Claude Mythos AI model has discovered 271 vulnerabilities in Firefox.

The vulnerabilities, identified with an early version of Claude Mythos Preview, were patched in the popular web browser this week with the release of version 150.

More than 40 CVEs have been addressed in Firefox 150, but only three are credited to Claude in the official advisory: CVE-2026-6746, CVE-2026-6757, and CVE-2026-6758. 

This indicates that many of the 271 bugs are likely lower-severity issues or flaws that don’t meet the threshold for a public CVE. This can include defense-in-depth issues, hardening, or bugs in non-exploitable code paths.

Mozilla has not shared any information on the type or nature of the vulnerabilities, but has made an important clarification. 

“Encouragingly, we also haven’t seen any bugs that couldn’t have been found by an elite human researcher. Some commentators predict that future AI models will unearth entirely new forms of vulnerabilities that defy our current comprehension, but we don’t think so,” Firefox CTO Bobby Holley noted.

Advertisement. Scroll to continue reading.

The fact that Claude Mythos found so many Firefox vulnerabilities is not surprising. When Anthropic released Mythos, the AI giant said the new frontier model can autonomously discover thousands of zero-day vulnerabilities.

That is why the company decided to withhold its public release and instead offer it only to a relatively small number of major organizations through a program called Project Glasswing.    

The list of companies in Project Glasswing includes AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks.

[ Read: OpenAI Widens Access to Cybersecurity Model After Mythos Reveal ] 

Palo Alto Networks has also shared some preliminary data from testing Mythos, saying that in terms of vulnerability discovery it accomplished the equivalent of a year’s worth of pentesting in less than three weeks.

The cybersecurity company also noted that the AI has impressive vulnerability-chaining capabilities, combining medium- and low-severity issues into a critical exploit. 

In addition, Mythos can identify logic-based issues that traditional tools may not detect.

“Within six months, advanced AI models with deep cybersecurity capabilities will become commonplace. Organizations that have not put appropriate safeguards in place will face an entirely new class of risk across their enterprise and critical infrastructure,” said Lee Klarich, chief product and technology officer at Palo Alto Networks.

Klarich pointed out that similar advances will likely come from other AI companies and the models may not be as restricted as Mythos. 

In addition, there are already some reports of Mythos being accessed by unauthorized users.

Related: ‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks

Related: ‘Mythos-Ready’ Security: CSA Urges CISOs to Prepare for Accelerated AI Threats

Related: CoChat Launches AI Collaboration Platform to Combat Shadow AI

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.