Mozilla has deployed an artificial intelligence system to identify security flaws in the Firefox web browser. The company used Anthropic's Mythos model to scan the codebase over a two-month period. This automated process uncovered 271 distinct vulnerabilities within the software.
Security experts classified 180 findings as high severity.
The discovery tool operated within a custom agent harness developed by Mozilla. This environment provided the large language model with specific tools, including Firefox sanitizer builds, to guide its analysis. Mozilla claims the system achieved almost no false positives due to a two-stage verification process involving a second AI model.

Security experts classified 180 of the findings as high severity, designated as sec-high. Another 80 issues fell into the moderate category, known as sec-moderate. The remaining 11 vulnerabilities were rated as low severity, or sec-low. Mozilla published 12 detailed Bugzilla reports that include test cases for memory safety issues.
Critics note the lack of assigned CVE numbers for the issues.
Mozilla CTO Brian Grinstead stated that AI-based vulnerability detection can end the era of zero-day exploits. He argued that this technology gives the defense side a decisive opportunity to win. Grinstead emphasized that there is no marketing intent behind the release and that the results are based on clear verification criteria.

Critics have pointed out that Mozilla did not assign CVE numbers to the 271 vulnerabilities. Mozilla treats these internally found issues as patch bundles rather than assigning individual identifiers. Some observers suggest the public release of only 12 reports may be selective, though Mozilla maintains the findings are comprehensive.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.