Mozilla's Firefox 150 Ships with 151 Anthropic-Found Bugs Squashed

Image: Bbc
Main Takeaway
Anthropic's restricted Mythos model helped Mozilla patch 151 bugs—22 rated critical—before Firefox 150 went live.
Jump to Key PointsSummary
What Mozilla Actually Fixed
Mozilla rolled Firefox 150 out this week carrying patches for 151 bugs that had never been reported. Anthropic’s yet-to-ship Mythos model, running inside a sealed red-team environment, produced the findings. Twenty-two of the issues reached the highest severity tier; the rest were medium- and low-risk crashes or memory-safety gaps. All fixes landed in the release branch before the browser shipped to the public.
How the Hunt Worked
Mozilla handed Anthropic a static export of the Firefox codebase plus a fuzzing harness that can replay every parser path a webpage can trigger. Mythos then spent roughly 48 hours generating test cases, crashing the browser thousands of times, and auto-triaging the root causes. Engineers at Mozilla reviewed each ticket, confirmed reproducibility, and rewrote the vulnerable code. The whole loop—AI finds, humans verify, patches land—took three weeks.
Why Mozilla Isn’t Worried About Skynet Yet
Firefox CTO Bobby Holley calls the exercise proof that defenders still hold the edge: the same tooling that can weaponize a flaw can also neuter it before release. Mozilla argues that scaling bug discovery simply moves the arms race earlier in the pipeline, giving maintainers time instead of attackers. The bigger risk, Holley warns, is developer disruption: teams must learn to triage AI-generated reports without drowning in noise.
Anthropic’s Tight Lid on Mythos
Despite the PR win, Anthropic has kept Mythos locked to a tiny whitelist. A Bloomberg scoop claims unauthorized users briefly accessed the model via a leaked debug token; Anthropic says no evidence of misuse surfaced and the token was revoked. The company still plans a staged rollout under the banner “Project Glasswing,” with AWS, Apple, Google, Microsoft, and Nvidia lined up for early access. Mozilla remains the only public customer so far.
What This Means for the Wider Ecosystem
Every major browser and OS vendor now knows that a single AI pass can surface hundreds of latent bugs. Google’s Chrome team already runs fuzz farms; Microsoft has hinted at similar LLM pilots. Security teams are bracing for a flood of low-signal reports and racing to automate triage. Meanwhile, bug-bounty platforms like HackerOne quietly raised payouts last month, anticipating that AI will shrink the pool of easy wins.
What Happens Next
Mozilla says the next milestone is letting Mythos run continuously on nightly builds, not just annual audits. Anthropic is drafting a policy paper on disclosure timelines—how long companies get to patch before the model’s findings can be shared. Regulators in the US and EU have requested briefings, worried that AI-accelerated vulnerability discovery could outpace responsible disclosure norms. The Firefox team, for now, is simply grateful the bugs were caught on their own turf.
Key Points
Mozilla patched 151 bugs (22 critical) in Firefox 150 after Anthropic’s Mythos model found them during a private red-team exercise.
Mythos generated the findings in 48 hours; Mozilla engineers spent three weeks validating and fixing the code.
Firefox CTO argues the same AI that can weaponize flaws can also neutralize them before release, preserving the defender advantage.
Anthropic keeps Mythos locked down; a leaked debug token briefly exposed it to unauthorized users, now revoked.
Project Glasswing will extend Mythos access to AWS, Apple, Google, Microsoft, and Nvidia before any public release.
Questions Answered
No. Anthropic has restricted the model to a small whitelist under Project Glasswing; Mozilla is the only publicly disclosed user so far.
Mozilla says all 151 were zero-day vulnerabilities with no evidence of prior exploitation.
Mythos produced findings in roughly 48 hours; Mozilla spent three weeks reviewing, reproducing, and landing patches.
Mozilla argues humans are still needed for validation, prioritization, and writing fixes; AI accelerates discovery but doesn’t replace judgment.
Anthropic claims the same model can be used defensively faster than offensively, but regulators and vendors are drafting stricter access policies.
Mozilla plans to integrate continuous AI red-team runs on nightly builds, not just periodic audits.
Source Reliability
47% of sources are highly trusted · Avg reliability: 75
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems