Behind the Scenes Hardening Firefox with Claude Mythos Preview

Simon Willison's Blog News

Summary

Mozilla used the Claude Mythos preview to systematically find and fix hundreds of security vulnerabilities in Firefox, dramatically increasing their bug-fix rate from around 20-30 per month to 423 in April 2026.

No content available
Original Article Export to Word Export to PDF
View Cached Full Text

Cached at: 05/08/26, 06:25 AM

# Behind the Scenes Hardening Firefox with Claude Mythos Preview Source: [https://simonwillison.net/2026/May/7/firefox-claude-mythos/](https://simonwillison.net/2026/May/7/firefox-claude-mythos/) 7th May 2026 \- Link Blog **[Behind the Scenes Hardening Firefox with Claude Mythos Preview](https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/)**\([via](https://lobste.rs/s/7zppv1/behind_scenes_hardening_firefox_with)\) Fascinating, in\-depth details on how Mozilla used their access to the Claude Mythos preview to locate and then fix hundreds of vulnerabilities in Firefox: > **Suddenly, the bugs are very good** Just a few months ago, AI\-generated security bug reports to open source projects were mostly known for being unwanted slop\. Dealing with reports that look plausibly correct but are wrong imposes an asymmetric cost on project maintainers: it’s cheap and easy to prompt an LLM to find a “problem” in code, but slow and expensive to respond to it\. It is difficult to overstate how much this dynamic changed for us over a few short months\. This was due to a combination of two main factors\. First, the models got a lot more capable\. Second, we dramatically improved our techniques for*harnessing*these models — steering them, scaling them, and stacking them to generate large amounts of signal and filter out the noise\. They include some detailed bug descriptions too, including a 20\-year old XSLT bug and a 15\-year\-old bug in the`<legend\>`element\. A lot of the attempts made by the harness were blocked by Firefox's existing defense\-in\-depth measures, which is reassuring\. Mozilla were fixing around 20\-30 security bugs in Firefox per month through 2025\. That jumped to 423 in April\. ![Bar chart titled "Firefox Security Bug Fixes by Month" with subtitle "All Sources • All Severities" on a dark purple background, showing monthly counts: Jan 2025: 21, Feb 2025: 20, Mar 2025: 26, Apr 2025: 31, May 2025: 17, Jun 2025: 21, Jul 2025: 22, Aug 2025: 17, Sep 2025: 18, Oct 2025: 26, Nov 2025: 19, Dec 2025: 20, Jan 2026: 25, Feb 2026: 61, Mar 2026: 76, Apr 2026: 423 — a dramatic spike in the final month.](https://static.simonwillison.net/static/2026/firefox-security.webp)

Similar Articles

Hardening Firefox with Claude Mythos Preview

Hacker News Top

Mozilla details how they used Claude Mythos Preview and other AI models to identify and fix a significant number of latent security bugs in Firefox, demonstrating a shift in the efficacy of AI for code hardening.

Quoting Bobby Holley

Simon Willison's Blog

Firefox 150 shipped with 271 security fixes found by Anthropic’s Claude Mythos Preview, marking a major AI-driven win for defensive security.

The zero-days are numbered

Lobsters Hottest

Mozilla used Anthropic's Claude Mythos Preview AI to find and fix 271 zero-day vulnerabilities in Firefox 150, marking a major shift in cybersecurity where AI enables defenders to decisively outpace attackers.