Anthropic’s Claude found 22 vulnerabilities in Firefox over two weeks
Summary
In a security partnership with Mozilla, Anthropic utilized its Claude Opus 4.6 model over two weeks to scan the Firefox codebase, successfully identifying 22 separate vulnerabilities, 14 of which were rated as high-severity. The team initially focused on the JavaScript engine before broadening the scope. While most bugs have been patched in Firefox 148, some fixes are slated for the next release. Interestingly, Claude proved much more adept at finding the flaws than creating functional exploits for them, with the team spending $4,000 in API credits to achieve only two successful proof-of-concept exploits. This exercise highlights the potential of AI tools in enhancing the security of complex, open-source projects like Firefox.
(Source:TechCrunch)