by

Claude just embarrassed Firefox in 20 minutes.

It took Anthropic’s most advanced artificial intelligence model about 20 minutes to find its first Firefox browser bug during an internal test of its hacking chops.

Anthropic’s team filed it, and Firefox’s developers replied fast: the bug was serious and they wanted a call.

Mozilla engineer Brian Grinstead said, “What else do you have? Send us more,”

Anthropic obliged. Over a two-week spell in January 2026, Claude Opus 4.6 found more high-severity bugs in Firefox than the rest of the world usually reports in two months, Mozilla said.

AI-powered tools are getting frighteningly good at spotting vulnerabilities and they are starting to rival seasoned security researchers. Some experts reckon the same speed will fuel a new wave of cyberattacks as bugs get found and exploited quicker than defenders can blink.

Claude’s bug binge started when Anthropic’s security lot decided it would be fun to point the model at a widely used, messy chunk of browser code that has been poked at for years.

Firefox is the modern successor to the web’s first commercial browser, Netscape Navigator. Its code now sits under the not-for-profit Mozilla Foundation.

Navigator launched its first bug bounty programme more than 30 years ago, paying cash for weaknesses that criminals could abuse. Mozilla typically pays as much as $6,000 (about €5,500) for high-severity bugs.

During the two weeks it scanned, Claude found more than 100 bugs in total, with 14 classed as “high severity”. If the right “exploit code” had been written, those could have fuelled a widespread attack on Firefox users.

In 2025, Firefox patched 73 bugs it rated as high severity or critical, which tells you the baseline for how ugly this stuff can get.

AI tools are a blessing and a curse for developers who already have enough grief. In January, the makers of Curl software binned their bug bounty programme, blaming “an explosion in AI slop reports”.

Fewer than one in 20 bugs reported in 2025 were real, Curl lead developer Daniel Stenberg said.

Curl lead developer Daniel Stenberg said, “The AI chatbots still easily hallucinate security problems. “But at the same time, there are quite capable AI-powered code analysers that find real things,” he said.

Anthropic’s researchers did not dump everything Claude unearthed on Mozilla’s doorstep, sticking to reproducible examples so the Firefox team could confirm the flaws without wasting their lives.

 

TOPICS:
ai security  ·  bug bounty  ·  claude opus  ·  cybersecurity  ·  exploit code  ·  Firefox  ·  Mozilla  ·  vulnerabilities

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews