Brief IA

Anthropic's Mythos Redefines Firefox Security

🤖 Models & LLM·Tom Levy·

Anthropic's Mythos Redefines Firefox Security

Anthropic's Mythos Redefines Firefox Security
Key Takeaways
1Mythos from Anthropic has revealed thousands of critical bugs in Firefox's code, some over ten years old.
2In April 2026, Firefox fixed 423 bugs thanks to Mythos, compared to only 31 the previous year.
3The model discovered complex vulnerabilities in the sandbox system, surpassing human researchers.
💡Why it mattersAI like Mythos could transform cybersecurity, strengthening software defenses against growing threats.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

When Anthropic unveiled its artificial intelligence model, Mythos, in April, it also issued a stern warning to the software development industry. Mythos has proven to be an extremely powerful tool for detecting software vulnerabilities, uncovering thousands of high-severity bugs that needed fixing before they could be made public.

Mozilla's security researchers, who work on the Firefox browser, recently provided a detailed overview of Mythos's impact on their security process. In a paper published on Thursday, Mozilla explained how Mythos enabled the discovery of a multitude of critical bugs, including some that had been buried in the code for over a decade.

This advancement represents a significant improvement over AI-based bug detection tools available just six months ago. Until now, these tools were often criticized for generating poor-quality reports and numerous false positives. However, Mozilla researchers claim that the latest generation of tools has crossed a threshold, particularly due to the ability of agentic systems to evaluate and filter their own results.

"It is hard to overstate how much this dynamic has changed for us in just a few months," the Mozilla researchers wrote. "First, the models have become much more capable. Then, we have significantly improved our techniques to leverage these models."

The results are striking: in April 2026, Firefox shipped 423 bug fixes, compared to just 31 exactly one year earlier. The researchers also published details on 12 of the bugs discovered, ranging from a pair of unusual sandbox vulnerabilities to a 15-year-old error in how the browser parses an HTML element.

Brian Grinstead, a distinguished engineer at Mozilla, told TechCrunch: "These things are actually suddenly very good. We see it in our own internal analysis, we see it in external bug reports, and we see it in all sorts of signals across the industry."

The fact that the system helped reveal vulnerabilities in Firefox's sandbox is particularly impressive, given the complexity of an attack that exploits it. To find sandbox vulnerabilities, the model must write a compromised patch for the browser, then attack the most secure part of the software with the newly implemented code. Finding and demonstrating the bug is a delicate multi-step process that requires both creativity and attention.

To put this in context, Mozilla's bug bounty program pays researchers who can find a bug in Firefox's sandbox up to $20,000 — the highest reward available. Despite this bounty, Grinstead claims that Mythos finds more sandbox issues than human researchers ever have. "We get them," he said to TechCrunch, "but not at the volume we are capable of finding with this technique."

Notably, the Firefox team still does not use AI to fix bugs, despite the well-documented advancements in AI-based coding tools. The team asks the AI to code patches for each bug, but the resulting code generally cannot be deployed directly and instead serves as a template for a human engineer.

"For the bugs we are discussing in this article, each is an engineer writing a patch and an engineer reviewing it," Grinstead states. "We haven't found that to be automatable."

It is still unclear how emerging AI capabilities will change the balance of power in cybersecurity. A month after the unveiling of Mythos, most of the discovered bugs have likely not been fixed, making it difficult to grasp the extent of their impact. Anthropic has been scrupulous in adhering to responsible disclosure standards, but it is likely that malicious actors are using similar techniques behind the scenes, even if the models they use are not quite as good.

Speaking at a recent event, Anthropic CEO Dario Amodei was optimistic that the new tools would ultimately favor defenders. "If we manage this correctly, we could be in a better position than we started, because we have fixed all these bugs. There is only a limited number of bugs to find," Amodei said. "So I think there is a better world on the other side of this."

After addressing concrete details, Grinstead has a more measured view: "It's useful for both attackers and defenders, but having the tool available shifts the advantage a bit toward defense. Realistically, no one knows the answer to that yet."

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.