CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Anthropic AI Model Discovers 22 Firefox Vulnerabilities

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Anthropic, in partnership with Mozilla, identified 22 security vulnerabilities in Firefox using its Claude Opus 4.6 AI model. The vulnerabilities, discovered over two weeks in January 2026, include 14 high-severity, 7 moderate-severity, and 1 low-severity issues. These were addressed in Firefox 148, released late last month. The AI model detected a use-after-free bug in the browser's JavaScript within 20 minutes, highlighting its efficiency in vulnerability discovery. Anthropic also tested the AI's ability to develop exploits from the identified vulnerabilities, finding that it could only successfully create exploits in two cases out of several hundred attempts. The company emphasized the cost-effectiveness of identifying vulnerabilities compared to exploit development. One of the vulnerabilities, CVE-2026-2796, is a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8. Mozilla confirmed the AI-assisted approach discovered 90 additional bugs, most of which have been fixed.

Timeline

  1. 07.03.2026 13:21 1 articles · 4h ago

    Anthropic AI Model Identifies 22 Firefox Vulnerabilities

    Anthropic, in partnership with Mozilla, discovered 22 vulnerabilities in Firefox using its Claude Opus 4.6 AI model. The vulnerabilities, discovered over two weeks in January 2026, include 14 high-severity, 7 moderate-severity, and 1 low-severity issues. These were addressed in Firefox 148, released late last month. The AI model detected a use-after-free bug in the browser's JavaScript within 20 minutes, highlighting its efficiency in vulnerability discovery. Anthropic also tested the AI's ability to develop exploits from the identified vulnerabilities, finding that it could only successfully create exploits in two cases out of several hundred attempts. The company emphasized the cost-effectiveness of identifying vulnerabilities compared to exploit development. One of the vulnerabilities, CVE-2026-2796, is a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component with a CVSS score of 9.8. Mozilla confirmed the AI-assisted approach discovered 90 additional bugs, most of which have been fixed.

    Show sources

Information Snippets