Mozilla says its Firefox 150 release includes fixes for 271 vulnerabilities identified using early access to Anthropic's Mythos Preview
The Firefox team doesn't think emerging AI capabilities will upend cybersecurity long term, but they warn that software developers are likely in for a rocky transition.
WiredLily Hay Newman
Context & Ripple Effects
Mozilla’s use of Anthropic models to find Firefox flaws had already produced more than 100 reported bugs in a two-week January test, including 14 high-severity issues. The later April reporting says Mythos and other models helped Mozilla identify and ship 423 security fixes, versus 31 in the comparable prior-year period.
Anthropic has positioned Mythos as a general-purpose model with vulnerability-finding capability across major operating systems and browsers, and launched Project Glasswing to apply that capability to finding and fixing software flaws. Firefox is therefore an early, concrete test of whether model-assisted discovery can be absorbed into a real maintainer’s patch-and-release workflow.
First-order effects
Firefox 150 delivers fixes for 271 vulnerabilities found with early access to Mythos Preview, reducing known exposure for Firefox users once they update.
Mozilla’s security team must triage, validate, prioritize, and patch a much larger AI-assisted finding set; Anthropic gains a production-software example for Mythos’s defensive use.
Second-order effects
If model-assisted discovery continues to raise the volume of credible findings, browser and software maintainers will face pressure to expand remediation capacity rather than treat vulnerability discovery as the binding constraint.
Early access to capable security models becomes operationally consequential: vendors and customers will need controls around who can use them and how discovered flaws are handled before disclosure.
Third-order effects
The episode points toward vulnerability management shifting from periodic, human-limited research toward continuous AI-assisted discovery paired with automated and human-led remediation; the transition may be uneven because patch validation and release processes do not scale automatically.
As the same frontier capabilities are framed for broad vulnerability discovery, access governance and coordinated disclosure practices could become more central to cybersecurity competition and safety policy.
The trend: Frontier AI is moving from a supplementary security-research tool into the software-maintenance pipeline, increasing both defensive discovery capacity and the need for controlled deployment.
Great piece by the Mozilla team on their use of the Mythos preview: — They have found that this gen of tools can identify vulns in arbitrary cateogries …
Remember I mentioned that there were ~90 bugs fixed in Edge Chromium this last patch Tuesday? Responsible dev teams are going to find and fix a ton of bugs; eventually attackers are going to use these models to find what devs haven't [embedded post]
“Computers were completely incapable of doing this a few months ago, and now they excel at it. We have many years of experience picking apart the work of the world's best security researchers, and Mythos Preview is every bit as capable.”
It took me a while to find a description of what these fixes actually were and whether they were critical vulnerabilities. For others who might be interested, here's the security fixes part of the release notes: — www.mozilla.org/en-US/securi...
Mozilla has essentially endorsed Anthropic's claims about Mythos after the model found 271 vulnerabilities in the Firefox codebase. — But instead of seeing Mythos as a zero-day doomsday, CTO Bobby Holley hails it as a bounty for security auditing:
Mozilla just reported that Anthropic's Mythos model identified 271 security vulnerabilities. It's an incredible figure. — Yet Mozilla downplays this massive haul, claiming Mythos found nothing a human couldn't, despite making their code look like it had more holes than a block…
“Now a powerful new capability has arrived—and as we've seen repeatedly in tech, there's the risk that organizations with resources will receive it first and learn to protect themselves, while others are left vulnerable.”
Interesting view from Firefox on The Cyber AI Reckoning. Bobby Holley says, “This is a transitory moment that is difficult and requires coordinated focus and a lot of grit to get through, but I think that it is a finite moment, even as the models become more advanced” www.wired.…
NEW: Mozilla has already used Mythos to find hundreds of bugs, which is good and interesting in its own right and also points up that contra some catastrophizing coverage, it isn't only attackers who will have access to these capabilities. @lhn.bsky.social has the news:
BREAKTHROUGH: Mozilla Used Anthropic's Secret Mythos AI To Find 271 Security Vulnerabilities In Mozilla Firefox In A Single Pass, And Says Defenders Can Finally Win 🤯🔥
It wasn't clear in the Wired article or in the Mozilla blog post how serious these 271 vulnerabilities in Firefox were. It looks like they were important but not critical (in the details in the release notes in the quoted post below). — www.wired.com/story/mozill... [embedded…