Claude Finds 22 Firefox Vulnerabilities in Two Weeks

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic identified 22 separate vulnerabilities in Firefox through a security partnership with Mozilla, 14 of which were classified as high-severity
- Mozilla has already fixed most of the bugs in Firefox 148, released in February, though a few fixes are deferred to the next release
- Anthropic's team deployed Claude Opus 4.6 over two weeks, beginning with the JavaScript engine before expanding to other portions of the Firefox codebase
- Firefox was selected as the target because it ranks as both a complex codebase and one of the most well-tested and secure open-source projects in the world
- Claude Opus proved far stronger at finding vulnerabilities than at exploiting them — the team burned $4,000 in API credits attempting proof-of-concept exploits and succeeded in only two cases
- The results illustrate how AI tools can accelerate security auditing for open-source projects, even as they generate a flood of low-quality merge requests alongside the useful ones
Why it matters: For Mozilla, the partnership surfaced 14 high-severity vulnerabilities now patched in Firefox 148 at a speed and cost far below traditional security audits. The $4,000 exploit-failure rate reveals a sharp asymmetry: Claude Opus found bugs far more effectively than it could construct working exploits, with only 2 successes across that spend. For open-source maintainers, the takeaway is that AI-assisted auditing is becoming essential just to keep pace with their own attack surfaces — but the same tools also generate noise that maintainers must filter.




