Mozilla Used Anthropic’s Mythos to Find and Fix 271 Bugs in Firefox
Anthropic’s Mythos Helps Mozilla Tackle Firefox Vulnerabilities
Mozilla has announced that its recent Firefox 150 release comes with fixes for 271 vulnerabilities, all identified using Anthropic’s Mythos Preview—a new AI-powered tool designed to uncover faults in software. While the Firefox team believes that AI's impact on cybersecurity may be temporary, they acknowledge that developers must brace for dramatic changes as automated tools reveal hidden issues at an unprecedented scale.
AI Ushers in a New Era of Software Review
The Firefox team, led by CTO Bobby Holley, explains that the arrival of advanced AI offers the potential to find virtually every bug that could lead to security vulnerabilities. Previously, a mix of manual assessments and traditional automated techniques like fuzzing were employed to locate flaws, but those methods had their limits. New AI models from companies such as Anthropic and OpenAI are now being released—albeit in limited private previews—because their powerful bug-hunting capabilities could benefit both defenders and attackers.
Holley likens this phase to a 'bootcamp,' where software must undergo rigorous review using these new AI tools to uncover long-buried bugs. The hope is that addressing vulnerabilities now, while access is restricted, can help protect users before malicious actors exploit the same AI advancements.
Challenges for Open Source and Smaller Projects
Open source software, like Firefox, could be particularly vulnerable, since many projects are maintained by small teams or even a single person. Industry leaders are bracing for a challenging transition—some have considered reallocating thousands of engineers to tackle vulnerabilities revealed by AI. Unfortunately, smaller projects may lack the resources or expertise to keep up, potentially widening the security gap.
As highlighted by Mozilla CTO Raffi Krikorian, the underlying economic dynamics have not changed: much of the world’s critical software is still maintained by unpaid volunteers, while larger companies may be able to secure their products first, potentially leaving the broader open source community exposed.
Collaboration and Human-Centric Solutions
Mozilla is working to support open source maintainers, sharing knowledge and tools informally where possible. Ultimately, Holley emphasizes that technology alone cannot address every challenge—collaborative, community-driven efforts are essential to ensure the safety and reliability of open source software in this era of intelligent vulnerability discovery.
For a more in-depth look at this story, read the full article by Lily Hay Newman at WIRED.