Mozilla says AI helped deliver 423 Firefox security fixes in April
Mozilla says Anthropic’s Claude Mythos Preview and other AI models helped it identify and ship 423 Firefox security bug fixes in April, marking a major acceleration in the browser maker’s security work.
The company said the April total included 271 bugs announced two weeks earlier, 41 externally reported bugs, and 111 additional issues found through a mix of Claude Mythos Preview, other models, and traditional techniques such as fuzzing. Mozilla said the results represented a sharp increase on earlier monthly totals, including 76 fixes in March and far lower average monthly figures across the previous year.
The work follows Mozilla’s collaboration with Anthropic on using frontier AI models to scan Firefox for latent security vulnerabilities. Mozilla had previously reported that Anthropic’s Claude Opus 4.6 helped find 22 security-sensitive Firefox bugs in version 148, and said its latest work with Mythos Preview showed a further leap in capability.
According to Mozilla, the breakthrough was not simply a matter of pointing an AI model at the Firefox codebase and waiting for results. The company developed a custom harness to guide the model through a workflow more similar to that used by human security researchers. The system gave the model access to files likely to contain issues and asked it to create test cases that could then be checked by fuzzing tools.
That harness appears to have been critical. Mozilla said earlier AI bug-hunting systems often produced low-quality or superficial reports, creating what security teams sometimes describe as noise. With the new workflow, Mozilla said the output was far more useful, with few false positives and a much higher rate of actionable findings.
Some of the issues identified were long-standing flaws that had survived years of traditional security review. Reports on Mozilla’s work note that some bugs had been present for 15 to 20 years, including issues that required chaining multiple vulnerabilities together before they became dangerous in practice.
That kind of vulnerability chain is one of the reasons tools such as Mythos are drawing intense interest. Traditional fuzzing can be effective at finding crashes or narrow bug classes, but complex exploit chains often require broader reasoning about how separate flaws interact. AI models with larger context windows and stronger code reasoning may be able to help researchers uncover those relationships faster.
Mozilla has framed the results as a potential shift in the balance between defenders and attackers. In an April blog post, the Firefox team argued that AI security tools could help defenders find and fix latent vulnerabilities more quickly, reducing the number of exploitable zero-days available to malicious actors.
Anthropic has described Mythos Preview as a frontier cybersecurity model capable of identifying sophisticated vulnerabilities and, in some cases, helping develop working exploits. Because of those capabilities, the company has limited access to select partners through Project Glasswing rather than releasing the model broadly.
Mozilla’s results show the defensive value of that capability, but also underline the need for caution. A model powerful enough to find deeply buried browser flaws could be valuable to software maintainers, but the same class of capability could also be misused by attackers if made widely available without safeguards.
The company also stressed that Mythos is not a magic solution. The model still required human direction, integration into Mozilla’s existing security workflows, and verification through established tools and engineering review. It did not simply replace security researchers. Instead, it amplified their ability to search, test and fix vulnerabilities at scale.
The findings may have implications beyond Firefox. Modern browsers are among the most complex and security-sensitive applications in everyday use, sitting between users and almost everything they do online. If AI-assisted vulnerability discovery can meaningfully improve browser security, similar methods may soon become standard across operating systems, cloud platforms, open-source infrastructure and enterprise software.
For now, Mozilla’s April bug-fixing surge offers one of the clearest public examples of AI being used not just to talk about cybersecurity, but to materially improve a major software product. The lesson is not that AI can secure code on its own. It is that, when properly harnessed by expert teams, it may help defenders find dangerous flaws faster than ever before.
Photo Credit: DepositPhotos.com
