Skip to content

Claude Mythos finds 271 security vulnerabilities in Mozilla Firefox, versus 22 for Claude Opus 4.6

Person working on coding and cyber security on a laptop and two monitors at a wooden desk with notes and plants.

Using Claude Opus 4.6, Mozilla identified 22 security vulnerabilities in Mozilla Firefox. Claude Mythos, however, uncovered 271.

Anthropic’s Claude Mythos AI is reportedly so capable that the company has chosen not to make it available to the public yet. It can match cybersecurity experts when it comes to identifying security weaknesses in software. A select group of organisations is nevertheless already able to test this artificial intelligence to strengthen its defences, including Mozilla, the developer of the Firefox browser.

Although the announcement of Claude Mythos’s capabilities was initially met with some scepticism, Mozilla has now shown just how useful the model could be for improving software security - provided it does not fall into the wrong hands. Mozilla found 22 security vulnerabilities using Claude Opus 4.6, one of Anthropic’s public-facing models. With Claude Mythos, by contrast, it discovered 271 flaws in Firefox.

A huge task ahead for online services

Mozilla’s publication also gives online services that may use Mythos to reinforce their defences an idea of the work ahead. “As these capabilities become widespread among defenders, many more teams are now feeling the same sense of vertigo we felt when these findings came to light. For a well-protected target, a single one of these bugs would have been enough to trigger a red alert in 2025; so, when they multiply like this, one starts to wonder whether it is still possible to keep pace,” Mozilla says.

Organisations will need to reassess their priorities and focus on fixing vulnerabilities identified by Mythos or comparable technologies. Mozilla has ultimately completed this task: Firefox 150 includes patches for all 271 vulnerabilities that were found.

Claude Mythos reaches elite level, but no further

According to Mozilla, Mythos’s key advantage is that, for the first time, an AI can carry out work that would ordinarily require elite cybersecurity researchers and take a great deal of time. Mozilla also stresses, however, that Mythos has not yet identified security vulnerabilities that the best cybersecurity specialists could not have found themselves.

In any case, while media coverage of Claude Mythos has largely focused on the risks, Mozilla is more optimistic. It believes the technology will improve the security of online services rather than undermine it. “It may seem frightening in the short term, but it is ultimately excellent news for defenders. The gap between flaws detectable by machines and those detectable by humans favours the attacker, who can devote several months of costly human effort to finding a single vulnerability. Closing that gap reduces the attacker’s long-term advantage by making all discoveries inexpensive,” Mozilla states.

Anthropic is already preparing a Claude Mythos release

For now, it remains unknown when Anthropic will launch Claude Mythos, or a comparable technology, for the general public. The AI laboratory is already preparing for that possibility, however.

Claude Opus 4.7, the newest version of its public model, includes safeguards that prevent use of the AI when behaviour posing cybersecurity risks is detected. The aim is to test whether these measures can also be applied to secure models such as Mythos.

While Mythos stands out because of its cybersecurity capabilities, it remains a general-purpose model whose performance could improve the automation of many other tasks.

What we think

Mozilla’s assessment is noteworthy because it suggests that Claude Mythos could eventually make the digital space safer. At present, however, concern around the world is focused instead on the cyberattack risks that would arise if this AI model, or similar technology, ended up in the wrong hands.

Comments

No comments yet. Be the first to comment!

Leave a Comment