Skip to main content
Live
Main content

Anthropic's Mythos found 271 vulnerabilities in Firefox 150 before release

Mozilla's CTO says the AI model matched elite human researchers — and calls it a turning point that every codebase will have to face.

Jaeden Schafer
Editor in Chief · · 4 min read

Mozilla shipped Firefox 150 this week with patches for 271 security vulnerabilities identified by Anthropic's Mythos Preview, the unreleased model Anthropic has so far limited to a small group of industry partners. Firefox CTO Bobby Holley disclosed the figure in a Tuesday blog post, arguing the model is "every bit as capable" as the world's top human security researchers. For comparison, Anthropic's Opus 4.6 found 22 security-sensitive bugs in Firefox 148 last month.

The jump is the point. Holley said many of the bugs Mythos surfaced could theoretically have been found by fuzzing or by an elite researcher grinding through source code for months. Mythos found them by reading the Firefox 150 codebase directly, at a cost that collapses the economics of vulnerability hunting on both sides of the fence.

Anthropic has been deliberately slow-walking access. Mythos Preview is only available to select partners, and the company has convened an industry working group called Project Glasswing to coordinate the rollout. Mozilla got access through a direct collaboration with Anthropic rather than through Glasswing itself.

Key facts

  • 01Anthropic. A key thread of reporting in this story.
  • 02Mozilla. A key thread of reporting in this story.
  • 03Firefox. A key thread of reporting in this story.

Holley's framing is that every serious codebase is about to run a one-time gauntlet. "Every piece of software is going to have to make this transition, because every piece of software has a lot of bugs buried underneath the surface that are now discoverable," he told Wired. He says he has spoken with engineering leaders at large companies who plan to pull thousands of engineers off roadmap work for six months to do exactly that.

Anthropic's Opus 4.6 surfaced 22 security-sensitive bugs in Firefox 148 last month. Mythos Preview surfaced 271 in Firefox 150 — a 12x jump in one model generation.
Jaeden Schafer

The uncomfortable part is open source. Widely deployed projects are often maintained by one or two unpaid volunteers, and abandonware gets no maintenance at all. Mozilla CTO Raffi Krikorian argued in a New York Times essay last week that the maintainer "who gave 20 years of his life" to code running inside products used by billions doesn't have Mythos access — and should.

Holley claims Firefox has "rounded the curve" thanks to its head start, and expects future models to find only marginal additions. That's a strong claim, and it only holds if attackers don't get access to comparable capability before defenders finish their pass. Anthropic's staged release is a bet that they won't.

The real story here is an economic inversion. For years, the defender's job was to make bug-finding expensive enough that only well-funded attackers could afford it. Mythos drops that price to near zero for anyone who has the model — which makes who gets the model, and when, the most important security question of the next year.

Related · from this week
Mozilla details how Anthropic's Mythos found 271 Firefox bugs with almost no false positives
Jaeden Schafer · 5 min read →
ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from News

Anthropic logo
Security

Mozilla details how Anthropic's Mythos found 271 Firefox bugs with almost no false positives

Mozilla unhid 12 Bugzilla reports to back its claim that an agent harness wrapping Mythos has effectively eliminated AI vulnerability slop.

Jaeden Schafer5 min read
Anthropic logo
Security

Discord users gained unauthorized access to Anthropic's Mythos Preview model

Amateur sleuths used a Mercor breach and a guessed URL to reach restricted Anthropic models, according to a Bloomberg report.

Jaeden Schafer4 min read
Trump delays AI security executive order citing US competitiveness concerns
News

Trump delays AI security executive order citing US competitiveness concerns

The president scrapped a planned signing after objecting to language requiring advance model sharing with government.

Jaeden Schafer4 min read