Claude Opus 4.6 finds 22 Firefox vulnerabilities with Mozilla
In two weeks Claude Opus 4.6 found 22 Firefox vulnerabilities, 14 rated high severity, but turned only two into crude exploits after hundreds of attempts.
Joint work with Mozilla, in which 14 of the 22 bugs were high severity, almost a fifth of all high-severity Firefox bugs remediated in 2025. Exploit attempts cost about $4,000 in credits and succeeded twice, only in a test environment with sandboxing removed. For that model, finding is far cheaper than exploiting.
- Date
- Friday, 6 March 2026
- Lab
- Anthropic
- Kind
- paper
- Access
- paper only
Figures
| Measure | Value | Measured by |
|---|---|---|
| Firefox vulnerabilities found in two weeks | 22 (14 high severity) Mozilla assigned the severity ratings | company |
| Exploit development success | 2 of several hundred runs about $4,000 in API credits; sandbox disabled in test | company |
Companion Frontier Red Team post reverse-engineers the CVE-2026-2796 exploit. By May 2026 Mozilla found 271 Firefox 150 vulnerabilities while testing Mythos Preview, over ten times what it found in Firefox 148 with Opus 4.6 (Glasswing update).
Sources
This record was checked against its sources on 6 October 2026. How we check