Firefox 150: Mythos AI found 271 vulnerabilities before release

Mozilla is convinced that AI technologies will now provide users with much more security. In this way, a total of 271 vulnerabilities were identified and fixed before the release of Firefox 150.
Software comes more securely to the user
The company worked with the AI developer Anthropic and got early access to its new AI model Mythos. This is said to be particularly good at uncovering security problems in software and has been the subject of heated discussions in the industry for weeks. The result of the Mythos analysis of the as yet unpublished Firefox source code significantly exceeded previous AI systems: For comparison, an older Anthropics model only identified 22 security-related errors when analyzing an earlier browser version.
Mozilla chief technology officer Bobby Holley spoke to US magazine Wired of a possible turning point in the battle between attackers and defenders in cyberspace. For decades there was a balance, as both finding vulnerabilities and exploiting them were time-consuming. With powerful AI, this ratio could now shift in favor of the defenders. Traditionally, security gaps are discovered either through automated testing procedures or by highly specialized experts. However, both methods are time-consuming and costly. According to Holley, Mythos can take on many of these tasks much more efficiently, replacing months of analysis work.
Faster and cheaper
Mozilla did not provide any details about the specific danger of the discovered vulnerabilities. Nevertheless, the sheer number of problems identified is considered remarkable. This is particularly relevant for open source projects, whose publicly accessible code can in principle be more easily analyzed by AI systems, while at the same time there are often only limited human resources available for security checks.
Holley emphasized that AI-supported security analyzes are likely to become the standard in the future. Software manufacturers have to prepare for this, as practically every application contains hidden errors that are now easier to find. Even though future AI models may become even more powerful, Mozilla believes it is well prepared by adopting the technology early.