Anthropic AI Model Discovers 22 Firefox Vulnerabilities
Summary
Hide ▲
Show ▼
Anthropic, in partnership with Mozilla, identified 22 security vulnerabilities in Firefox using its Claude Opus 4.6 AI model. The vulnerabilities, discovered over two weeks in January 2026, include 14 high-severity, 7 moderate-severity, and 1 low-severity issues. These were addressed in Firefox 148, released late last month. The AI model detected a use-after-free bug in the browser's JavaScript within 20 minutes, highlighting its efficiency in vulnerability discovery. Anthropic also tested the AI's ability to develop exploits from the identified vulnerabilities, finding that it could only successfully create exploits in two cases out of several hundred attempts. The company emphasized the cost-effectiveness of identifying vulnerabilities compared to exploit development. One of the vulnerabilities, CVE-2026-2796, is a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8. Mozilla confirmed the AI-assisted approach discovered 90 additional bugs, most of which have been fixed.
Timeline
-
07.03.2026 13:21 1 articles · 4h ago
Anthropic AI Model Identifies 22 Firefox Vulnerabilities
Anthropic, in partnership with Mozilla, discovered 22 vulnerabilities in Firefox using its Claude Opus 4.6 AI model. The vulnerabilities, discovered over two weeks in January 2026, include 14 high-severity, 7 moderate-severity, and 1 low-severity issues. These were addressed in Firefox 148, released late last month. The AI model detected a use-after-free bug in the browser's JavaScript within 20 minutes, highlighting its efficiency in vulnerability discovery. Anthropic also tested the AI's ability to develop exploits from the identified vulnerabilities, finding that it could only successfully create exploits in two cases out of several hundred attempts. The company emphasized the cost-effectiveness of identifying vulnerabilities compared to exploit development. One of the vulnerabilities, CVE-2026-2796, is a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8. Mozilla confirmed the AI-assisted approach discovered 90 additional bugs, most of which have been fixed.
Show sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
Information Snippets
-
Anthropic discovered 22 vulnerabilities in Firefox using its Claude Opus 4.6 AI model.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
The vulnerabilities include 14 high-severity, 7 moderate-severity, and 1 low-severity issues.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
The vulnerabilities were addressed in Firefox 148, released late last month.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
The AI model detected a use-after-free bug in the browser's JavaScript within 20 minutes.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
Anthropic scanned nearly 6,000 C++ files and submitted 112 unique reports.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
The AI model could only develop exploits in two cases out of several hundred attempts.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
One of the vulnerabilities, CVE-2026-2796, is a JIT miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21
-
Mozilla confirmed the AI-assisted approach discovered 90 additional bugs, most of which have been fixed.
First reported: 07.03.2026 13:211 source, 1 articleShow sources
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model — thehackernews.com — 07.03.2026 13:21