Claude Opus 4.6 Uncovers 22 Firefox Flaws, Including 14 High-Severity
The project shows AI excels at finding bugs, not at producing real-world exploits.
Overview
- Mozilla fixed most of the reported issues in Firefox 148, with remaining patches scheduled for upcoming releases.
- Fourteen of the 22 vulnerabilities were rated high severity, nearly one-fifth of all high-severity Firefox fixes in 2025.
- Claude scanned nearly 6,000 C++ files, filed 112 reports, and flagged a JavaScript engine use-after-free in about 20 minutes.
- Hundreds of exploit-generation attempts and roughly $4,000 in API usage produced only two working exploits in controlled, sandbox-disabled tests.
- Mozilla says AI-assisted analysis also surfaced about 90 additional bugs that were mostly fixed, and it is piloting AI-assisted security reviews internally.