9 Sources
[1]
Anthropic's Claude found 22 vulnerabilities in Firefox over two weeks | TechCrunch
In a recent security partnership with Mozilla, Anthropic found 22 separate vulnerabilities in Firefox -- 14 of them classified as "high-severity." Most of the bugs have been fixed in Firefox 148 (the version released this February), although a few fixes will have to wait for the next
[2]
Anthropic's Claude Finds More Bugs in Firefox than Human Teams
As more and more industries seem to be waking up to the threat of AI-based automation, new data from browser maker Mozilla is showing how AI is proving proficient at identifying cybersecurity vulnerabilities in popular software. According to details shared by researchers at Mozilla, Anthropic's AI
[3]
Firefox finds a slew of new bugs with Claude's help
Now if only device makers would deliver higher quality components Thanks to Anthropic's AI and its bug-detecting abilities, Firefox users can now enjoy stronger security. Unfortunately, if browser crashes rather than security flaws are the problem, Claude probably can't help. Mozilla engineer
[4]
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model
Anthropic on Friday said it discovered 22 new security vulnerabilities in the Firefox web browser as part of a security partnership with Mozilla. Of these, 14 have been classified as high, seven have been classified as moderate, and one has been rated low in severity. The issues were addressed in
[5]
Mozilla says Claude AI uncovered over 100 Firefox bugs in just two weeks, including 14 high-severity flaws
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. The takeaway: While some companies are struggling with a flood of unreliable or hallucinated AI-generated bug reports, Mozilla is finding real value in bug-seeking bots. The foundation has begun
[6]
Anthropic says it found a heap of Firefox security flaws using new Claude tools, says 'AI is making it possible to detect severe security vulnerabilities at highly accelerated speeds'
* Anthropic Claude Opus 4.6 uncovers 22 Firefox security flaws * Mozilla confirmed 14 high-severity vulnerabilities patched in Firefox 148 * AI model demonstrated accelerated, human-like vulnerability detection Anthropic says it found almost two dozen vulnerabilities in the latest version of
[7]
Claude AI discovered 22 Firefox flaws. Here's how many it figured out how to exploit.
Claude AI discovered nearly two dozen vulnerabilities in Firefox, the Mozilla web browser. Anthropic teamed up with Mozilla to test the security of its browser, allowing its AI tool to probe for vulnerabilities. Read, in part, a blog post from Anthropic: "Claude Opus 4.6 discovered 22
[8]
Anthropic's Claude uncovers 22 Firefox security vulnerabilities
Why it matters: AI models are rapidly lowering the cost of finding software vulnerabilities, surfacing serious flaws even in heavily scrutinized projects like Firefox. Driving the news: Anthropic uncovered more than 500 previously unknown flaws across open-source projects while testing Claude Opus
[9]
Anthropic's Claude finds first Firefox bug in 20 mins during test, Mozilla devs call it serious
After Claude detected the first vulnerability, Anthropic reported it to Mozilla. Anthropic recently tested its artificial intelligence model, Claude Opus 4.6, to see its hacking capabilities. During the test, the AI found its first bug in the Firefox web browser within about 20 minutes. Claude's
Share
Copy Link
In a security partnership with Mozilla, Anthropic used Claude Opus 4.6 to identify 22 CVEs in Firefox over two weeks—14 classified as high-severity. The AI model detected more vulnerabilities than any single month in 2025, though it struggled to create working exploits. The findings highlight AI's growing role in cybersecurity while raising questions about future safeguards.
Anthropic has identified 22 Firefox vulnerabilities through a security partnership with Mozilla, marking a significant milestone in AI-assisted bug hunting. Using Claude Opus 4.6 over a two-week period in January 2026, the AI company discovered 14 high-severity flaws, seven moderate-severity issues, and one low-severity bug
1
. These findings resulted in 22 CVEs, with most bug fixes implemented in Firefox 148, released in February 20264
.
Source: Digit
The 14 high-severity bugs represent almost a fifth of the 73 high-severity vulnerabilities Mozilla fixed throughout 2025
2
. In fact, Claude AI discovered more Firefox vulnerabilities in two weeks than were reported in any single month in 2025, demonstrating how AI is making it possible to detect severe security vulnerabilities at highly accelerated speeds2
.The Anthropic team focused their efforts on Firefox's JavaScript engine before expanding to other portions of the codebase. According to Mozilla engineers Brian Grinstead and Christian Holler, Anthropic approached the Firefox team several weeks ago with a newly developed AI-assisted vulnerability detection system
3
. Despite mixed results with prior AI-assisted bug detection systems, this approach proved different—within hours, platform engineers began landing fixes3
.Source: TechSpot
Mozilla selected Firefox for testing because "it's both a complex codebase and one of the most well-tested and secure open-source projects in the world"
1
. The AI model detected a use-after-free bug in the browser's JavaScript engine after just 20 minutes of exploration, which was then validated by human researchers in a virtualized environment4
. By the end of the effort, Claude Opus 4.6 had scanned nearly 6,000 C++ files and submitted 112 unique reports4
.While Claude AI excelled at identifying bugs, it performed comparatively poorly at exploiting them. Anthropic spent approximately $4,000 in API credits attempting to develop proof-of-concept exploits, but Claude Opus 4.6 succeeded in only two cases
1
. These were "crude browser exploits" that would be unlikely to work in real-world scenarios due to existing AI safeguards and security features like sandboxing2
.
Source: Axios
One successful exploit targeted CVE-2026-2796, a just-in-time miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8
4
. However, Anthropic emphasized that this exploit only worked within a testing environment with intentionally removed security features3
. The company noted that the cost of identifying vulnerabilities is cheaper than creating exploits, and the model is better at finding issues than exploiting them4
.Related Stories
Beyond the 22 CVEs, the AI-assisted approach uncovered 90 additional low-priority bugs, bringing the total to over 100 Firefox bugs discovered in just two weeks
5
. Many of these consisted of assertion failures that overlapped with issues traditionally found through fuzzing, but the AI also identified distinct classes of logic bugs that fuzzers failed to catch4
.Mozilla views these findings as "clear evidence that large-scale, AI-assisted analysis is a powerful new addition to security engineers' toolbox"
4
. The organization plans to incorporate this new method into its broader security and development workflow, expecting Claude AI models and other advanced systems to help uncover additional issues in the future5
.While Mozilla has found value in bug-seeking bots, not all open-source projects share this positive experience. Daniel Stenberg, a lead developer at curl, reported "an explosion in AI slop reports," with fewer than one in 20 bugs reported to the company in 2025 being actually real
2
. "The AI chatbots still easily hallucinate security problems," Stenberg said2
.Anthropic's approach differs significantly from other AI-driven efforts by incorporating a task verifier to determine if exploits actually work, providing real-time feedback as the tool explores the codebase
4
. The company recently launched Claude Code Security in limited research preview, which can highlight vulnerabilities and suggest targeted software fixes for human review2
.Looking ahead, Anthropic acknowledged a critical concern: "Looking at the rate of progress, it is unlikely that the gap between frontier models' vulnerability discovery and exploitation abilities will last very long"
3
. If future language models break through this exploitation barrier, the company stated it will need to consider additional safeguards or other actions to prevent models from being misused by malicious actors3
. The Red Team collaboration demonstrates both the promise and potential risks of AI in cybersecurity, as the technology continues to advance at a rapid pace.Summarized by
Navi
[3]
07 May 2026•Technology

06 Feb 2026•Technology

06 Jun 2026•Technology

1
Science and Research

2
Technology

3
Policy and Regulation
