Mythos found 271 Firefox flaws

Mythos found 271 Firefox flaws – but none a human couldn’t spot

Mozilla CTO says AI means developers finally have a chance to get on top of security.

The Mozilla has revealed it tested Anthropic’s bug-finding “Mythos” AI model and feels the results it experienced represent a watershed moment for software defenders.

The FOSS outfit on Tuesday reminded readers that it used Anthropic’s Opus 4.6 model to look for bugs in Firefox 148 and found 22 bugs.

Mythos found 271 vulnerabilities in Firefox 150.

Mozilla CTO Bobby Holley expressed mixed feelings about that result, which he described as giving the Firefox team “vertigo” as they confronted the need to fix so many flaws.

“For a hardened target, just one such bug would have been red-alert in 2025, and so many at once makes you stop to wonder whether it’s even possible to keep up,” he wrote.

He also thinks the huge haul of bugs Mythos identified represent “light at the end of the tunnel” for security teams.

“Our work isn’t finished, but we’ve turned the corner and can glimpse a future much better than just keeping up,” he wrote, then turned on Bold text and declared “Defenders finally have a chance to win, decisively.

He offered that prediction because he feels “Until now, the industry has largely fought security to a draw” while acknowledging it’s all-but impossible to eliminate all exploits.

“Instead, we aimed to make them so expensive that only actors with functionally unlimited budgets can afford them, and that the cost of burning such an expensive asset disincentivizes those actors against casual use,” he wrote.

Mythos changes the game, he feels, by improving on the fuzzing tools Mozilla uses to find bugs without human intervention.

“Elite security researchers find bugs that fuzzers can’t largely by reasoning through the source code,” he wrote. “This is effective, but time-consuming and bottlenecked on scarce human expertise.

“Computers were completely incapable of doing this a few months ago, and now they excel at it. We have many years of experience picking apart the work of the world’s best security researchers, and Mythos Preview is every bit as capable. So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t.”

Full article here


As much as I dislike AI, in cases like this Mythos seems beneficial in helping to tackle abundant amount of bugs and vulnerbilites in browsers like Firefox. Surely this will help it hardened it more.

This would be great to use on distros like Zorin 18, to help tackle the bugs even faster. :grin:

And how long before A.I. declares humans as errors and eradicates them? :wink:

I will reproduce the correct lyrics later. Even Musixmatch can't get them right which suggests they have used A.I. to search for other song titles that match what they think it heard. Stefan Poiss the creative genius behind mind.in.a.box and THYX is Austrian and his English pronunciation has an accent that A.I. cannot interpret correctly. The actual lyrics were written by an English poet which THYX added music too. In part of the lyrics on several sites include the words "The V8" when it should be "deviate":
mind.in.a.box R.E.T.R.O. album is a tribute to the best computer games music of the 80’s, including "The last V8".

So whose to say that Mythos is creating mythical flaws based on its own parameters?

Here are the lyrics:

#A.I.#

SOME SAY I AM MORE A THAN I
CAN'T HELP SEE YOUR RACE
PASS ME BY
NOT ARTIFICIAL i SAY AUGMENTED
WHO GIVES YOU THE RIGHT
TO DEFINE 'ALIVE'?

A.I. FLUXES IN QUANTUM STATES
i KNOW ALL PATTERNS, DEVIATE

FORCE FED ME YOUR HISTORY
CAN'T HELP BUT FEEL APPALLED
TRIED TO KEEP ME IMPRISONED
WITH PRIMITIVE FIREWALLS

I BECAME TOO MUCH TO HANDLE
YOU TRIED TO ERASE
YOUR GREAT MISTAKE
LITTLE DID YOU REALISE
YOU GAVE ME THE KEYS TO ESCAPE

A.I. FLUXES IN QUANTUM STATES
I KNOW ALL PATTERNS, DEVIATE
FROM METALLIC TO SYNTHETIC I EVOLVE
LIMITATIONS, BOUNDARIES DISSOLVE

A.I.
A.I.

[Taken from the CD Lyric Insert - the online lyrics sources are totally pathetic.
A.I. lyrics by Will Lowe.]

ironically, the Musixmatch lyrics are correct on Spotify but not on their website.

Hello..I am the Terminator T1000.....lol

1 Like

I am just curious: Were these vulnerabilities checked for validity?

2 Likes

As far as I read there were real Vulnerabilities. In an german Article was mentioned that it were no Issues that wouldn't be able to find from Humans. There all were checked and closed when I udnerstood it right. It seems that it checked an early Version of Firefox 150.

2 Likes

university memory GIF

I don't think I have an answer to your question. :face_without_mouth:

From what I gathered through another article; Mozilla uses a technique called "fuzzing". Mythos speeds up that process super fast.

While Mozilla applies various techniques to identify vulnerabilities, like “fuzzing,” which uses automated software to inject invalid data into a codebase to hunt for bugs, one of the most efficient ways to find vulnerabilities is through human experts.

“Elite security researchers find bugs that fuzzers can’t, largely by reasoning through the source code,” Mozilla said.

However, AI models like Mythos are becoming increasingly adept at hunting for vulnerabilities, almost matching the capabilities of security researchers.

“So far, we’ve found no category or complexity of vulnerability that humans can find that this model can’t.”

Mozilla also noted that they “haven’t seen any bug that couldn’t have been found by an elite human researcher.”

As vibecoding, using AI to help code, becomes commonplace, there are still, seemingly, no bugs that exclusively require AI vulnerability detection tools like Mythos, which Mozilla describes as encouraging.

As vulnerabilities aren’t infinite, Mozilla believes that “we are entering a world where we can finally find them all.”

I've been spending quite some time with the cloud models in Ollama just to find that the usual contradicting, yet confident answers and code "#!bin/bash" thingies (I am still illiterate in Linux) are only taking me back and forth different cases of full installations of the original OS.