Mozilla said Firefox 150 includes fixes for 271 vulnerabilities identified during an initial evaluation of Anthropic’s Claude Mythos Preview. Wired also reported that the latest Firefox release includes protections for 271 vulnerabilities found with early access to Mythos Preview.
Since February, Mozilla said the Firefox team has been using Frontier AI models to find and fix latent security vulnerabilities in the browser. The company said an earlier collaboration with Anthropic used Opus 4.6 to scan Firefox and led to fixes for 22 security-sensitive bugs in Firefox 148. Mozilla described the Mythos work as part of that continued collaboration.
Anthropic partnership expands
Mozilla said it applied an early version of Claude Mythos Preview to Firefox as part of its ongoing work with Anthropic. According to the company, the findings created a sense of “vertigo” because even one such bug in a hardened target would have been a red alert in 2025. Mozilla said finding so many at once raised a serious question about whether teams can keep up.
At the same time, Mozilla said the experience also gave it hope. The company said teams may need to reprioritize everything else and focus single-mindedly on fixing issues, but argued there is “light at the end of the tunnel.” Mozilla added that its work is not finished, yet said it has turned a corner and can see a future that is better than simply keeping up.
Why Mozilla says it matters
Mozilla said the software industry has largely fought security to a draw until now. It said vendors of critical internet-exposed software like Firefox take security seriously, but also quietly accepted that bringing exploits to zero was unrealistic. Instead, Mozilla said the goal had been to make exploits so expensive that only actors with functionally unlimited budgets could afford them.
In Mozilla’s view, that happened because software security has been offensively dominant. The company said the attack surface is not infinite, but it is large enough to be difficult to defend comprehensively with the tools available so far. That leaves attackers with an asymmetric advantage because they only need to find one weakness.
Mozilla argued that cheaper, broader vulnerability discovery could change that balance. The company said a gap between machine-discoverable bugs and human-discoverable bugs favors attackers, because they can focus many months of costly human effort on finding a single flaw. Mozilla said closing that gap would erode the attacker’s long-term advantage by making discoveries cheap.
How Firefox is defended
Mozilla said Firefox relies on defense-in-depth, using multiple overlapping protections. It said each website runs in a separate process sandbox, while attackers try to combine bugs in rendering code with bugs in the sandbox to escape into a more privileged context. Mozilla also said it has led the industry in building and adopting Rust, but it cannot stop rewriting decades of C++ code.
The company said it pairs those engineering defenses with an internal red team that stays focused on automated analysis techniques. Mozilla said fuzzing has been fruitful in practice, but some parts of the code are harder to fuzz than others, which creates uneven coverage. It added that elite security researchers often find bugs that fuzzers cannot by reasoning through source code.
Mozilla said computers were incapable of that kind of reasoning only a few months ago, but now they “excel at it.” Bobby Holley wrote that Mozilla has many years of experience studying the work of top security researchers and said Mythos Preview is “every bit as capable.” Ars Technica separately highlighted that point in its coverage of Firefox 150, reporting that Mozilla’s CTO described the model that way.
What Mozilla says comes next
Mozilla said it has not seen any category or complexity of vulnerability that humans can find, and the model cannot. It also said it has not seen bugs that could not have been found by an elite human researcher. The company argued that this is encouraging because it suggests the model is closing a gap rather than uncovering entirely alien classes of flaws.
Mozilla also pushed back on the idea that future AI systems will necessarily find new forms of vulnerabilities beyond human understanding. It said software like Firefox is built in a modular way so humans can reason about its correctness, even if it is complex. Mozilla ended its post by saying the defects are finite and that defenders finally have a chance to win decisively.
Wired reported that Firefox 150 includes protections for the 271 vulnerabilities identified through early access to Mythos Preview. Mozilla said those fixes are part of this week’s Firefox 150 release. Gigazine also reported that Mozilla said Firefox 150 was officially released on April 22, 2026, and that the initial assessment found 271 vulnerabilities.
