Claude Mythos finds zero-days in every major OS and browser

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic announced Claude Mythos Preview alongside Project Glasswing, an effort to deploy the model to secure critical open-source and industry software before models with similar capabilities become broadly available.
- Claude Mythos Preview can identify and exploit zero-day vulnerabilities in every major operating system and web browser, including a 27-year-old bug in OpenBSD, per Anthropic's testing.
- The model chained four vulnerabilities into a browser exploit using a JIT heap spray that escaped both renderer and OS sandboxes, and autonomously obtained local privilege escalation on Linux by exploiting race conditions and KASLR bypasses.
- Anthropic engineers with no formal security training used Mythos Preview to find complete, working remote code execution exploits overnight after simply asking the model to look.
- Against the Opus 4.6 baseline, which had a near-0% autonomous exploit development success rate, Mythos Preview produced 181 working Firefox exploits versus Opus 4.6's 2 successes on the same Firefox 147 JavaScript engine bugs.
- On OSS-Fuzz benchmarks of ~7,000 entry points across ~1,000 repositories, Mythos Preview achieved full control flow hijack (tier 5) on 10 fully patched targets; Sonnet 4.6 and Opus 4.6 each reached only a single tier 3 crash.
- Over 99% of the vulnerabilities Mythos Preview discovered remain unpatched, which Anthropic says prevents it from disclosing technical details under its coordinated vulnerability disclosure process.
Why it matters: The jump from Opus 4.6's near-0% autonomous exploit success to Mythos Preview's 181 working Firefox exploits is a quantitative leap that Anthropic itself calls a 'watershed moment.' Because these capabilities emerged without explicit training, and 99% of found bugs remain unpatched, defenders have a narrow coordination window before attackers gain access to similarly capable models.




