AI Research Atlas

Claude Opus 4.6 finds 22 Firefox vulnerabilities with Mozilla

Anthropic · 6 March 2026

In two weeks Claude Opus 4.6 found 22 Firefox vulnerabilities, 14 rated high severity, but turned only two into crude exploits after hundreds of attempts.

Joint work with Mozilla, in which 14 of the 22 bugs were high severity, almost a fifth of all high-severity Firefox bugs remediated in 2025. Exploit attempts cost about $4,000 in credits and succeeded twice, only in a test environment with sandboxing removed. For that model, finding is far cheaper than exploiting.

Date
Friday, 6 March 2026
Lab
Anthropic
Kind
paper
Access
paper only

Figures

MeasureValueMeasured by
Firefox vulnerabilities found in two weeks22 (14 high severity)
Mozilla assigned the severity ratings
company
Exploit development success2 of several hundred runs
about $4,000 in API credits; sandbox disabled in test
company

Companion Frontier Red Team post reverse-engineers the CVE-2026-2796 exploit. By May 2026 Mozilla found 271 Firefox 150 vulnerabilities while testing Mythos Preview, over ten times what it found in Firefox 148 with Opus 4.6 (Glasswing update).

Sources

  1. www.anthropic.com/news/mozilla-firefox-security
  2. www.anthropic.com/research/exploit

This record was checked against its sources on 6 October 2026. How we check

Related