Claude Opus 4.6 found 14 high-severity Firefox bugs, nearly a fifth of all critical vulnerabilities fixed in 2025. Mozilla shipped fixes to hundreds of millionsClaude Opus 4.6 found 14 high-severity Firefox bugs, nearly a fifth of all critical vulnerabilities fixed in 2025. Mozilla shipped fixes to hundreds of millions

Anthropic AI Discovers 22 Firefox Vulnerabilities in Two Weeks

2026/03/06 19:13
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Anthropic AI Discovers 22 Firefox Vulnerabilities in Two Weeks

Tony Kim Mar 06, 2026 11:13

Claude Opus 4.6 found 14 high-severity Firefox bugs, nearly a fifth of all critical vulnerabilities fixed in 2025. Mozilla shipped fixes to hundreds of millions of users.

Anthropic AI Discovers 22 Firefox Vulnerabilities in Two Weeks

Anthropic's Claude Opus 4.6 identified 22 security vulnerabilities in Mozilla Firefox over a two-week period, with 14 classified as high-severity—representing nearly a fifth of all critical Firefox bugs remediated throughout 2025. The findings have already been patched in Firefox 148.0, protecting hundreds of millions of users.

The collaboration marks a significant milestone in AI-assisted security research. Within twenty minutes of initial exploration, Claude discovered a Use After Free vulnerability in Firefox's JavaScript engine—a memory flaw that could allow attackers to inject malicious code. By the time Anthropic researchers validated and submitted that first bug, the AI had already flagged fifty more unique crashing inputs.

Speed That Human Researchers Can't Match

Anthropic scanned nearly 6,000 C++ files and submitted 112 unique reports to Mozilla's Bugzilla tracker. The company chose Firefox specifically because it's one of the most rigorously tested open-source projects in existence—making it a harder benchmark than typical targets.

"Browser vulnerabilities are particularly dangerous because users routinely encounter untrusted content and depend on the browser to keep them safe," Anthropic noted in their announcement. The JavaScript engine presented an especially critical attack surface since it processes external code whenever someone browses the web.

Mozilla's security team adapted their processes mid-collaboration, eventually encouraging Anthropic to submit findings in bulk without manually validating each one. Most issues shipped fixes in Firefox 148, with remaining patches coming in future releases.

The Exploitation Gap—For Now

Here's where it gets uncomfortable. Anthropic also tested whether Claude could actually exploit the bugs it discovered. After spending roughly $4,000 in API credits across several hundred attempts, Opus 4.6 successfully developed working exploits in two cases—crude ones that only functioned in test environments with security features disabled, but functional nonetheless.

The AI proved far better at finding vulnerabilities than weaponizing them. That's good news for defenders, but Anthropic isn't sugarcoating the trajectory: "Looking at the rate of progress, it is unlikely that the gap between frontier models' vulnerability discovery and exploitation abilities will last very long."

What This Means for the Industry

The partnership comes amid Mozilla's broader push to counter AI industry giants. In late January 2026, Mozilla announced plans to deploy roughly $1.4 billion through Mozilla Ventures to fund AI startups focused on safety and transparency—positioning itself as a "rebel alliance" against closed-source AI dominance. Mozilla Ventures has already backed over 55 companies since launching in 2022.

Anthropic, meanwhile, closed a $30 billion Series G round in February 2026 at a $380 billion valuation, giving it substantial resources to expand cybersecurity initiatives. The company has already used Claude to discover vulnerabilities in other major projects including the Linux kernel.

For developers, the message is blunt: this window where AI finds bugs faster than it exploits them won't stay open indefinitely. Anthropic plans to expand its security work significantly, including direct outreach to open-source maintainers and a new Claude Code Security tool currently in limited preview. They're also hiring security researchers to scale these efforts.

Mozilla engineers have started experimenting with Claude internally for their own security testing—a telling sign of where browser security is headed.

Image source: Shutterstock
  • anthropic
  • mozilla
  • ai security
  • firefox
  • cybersecurity
Market Opportunity
4 Logo
4 Price(4)
$0.008136
$0.008136$0.008136
-0.59%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Silver Prices Edge Closer to a Pivotal Support and Resistance Test

Silver Prices Edge Closer to a Pivotal Support and Resistance Test

The post Silver Prices Edge Closer to a Pivotal Support and Resistance Test appeared on BitcoinEthereumNews.com. The silver market, although experiencing recent
Share
BitcoinEthereumNews2026/03/07 11:29
U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

The post U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam appeared on BitcoinEthereumNews.com. Crime 18 September 2025 | 04:05 A Colorado judge has brought closure to one of the state’s most unusual cryptocurrency scandals, declaring INDXcoin to be a fraudulent operation and ordering its founders, Denver pastor Eli Regalado and his wife Kaitlyn, to repay $3.34 million. The ruling, issued by District Court Judge Heidi L. Kutcher, came nearly two years after the couple persuaded hundreds of people to invest in their token, promising safety and abundance through a Christian-branded platform called the Kingdom Wealth Exchange. The scheme ran between June 2022 and April 2023 and drew in more than 300 participants, many of them members of local church networks. Marketing materials portrayed INDXcoin as a low-risk gateway to prosperity, yet the project unraveled almost immediately. The exchange itself collapsed within 24 hours of launch, wiping out investors’ money. Despite this failure—and despite an auditor’s damning review that gave the system a “0 out of 10” for security—the Regalados kept presenting it as a solid opportunity. Colorado regulators argued that the couple’s faith-based appeal was central to the fraud. Securities Commissioner Tung Chan said the Regalados “dressed an old scam in new technology” and used their standing within the Christian community to convince people who had little knowledge of crypto. For him, the case illustrates how modern digital assets can be exploited to replicate classic Ponzi-style tactics under a different name. Court filings revealed where much of the money ended up: luxury goods, vacations, jewelry, a Range Rover, high-end clothing, and even dental procedures. In a video that drew worldwide attention earlier this year, Eli Regalado admitted the funds had been spent, explaining that a portion went to taxes while the remainder was used for a home renovation he claimed was divinely inspired. The judgment not only confirms that INDXcoin qualifies as a…
Share
BitcoinEthereumNews2025/09/18 09:14
[Newspoint] Overpaid troll

[Newspoint] Overpaid troll

KAUFMAN. Former president Rodrigo Duterte's lawyer Nicholas Kaufman delivers his opening statement before the ICC Pre-Trial Chamber I on February 23, 2026.
Share
Rappler2026/03/07 11:00