Mozilla shipped Firefox 150 last month with an unprecedented security haul. The team fixed 423 bugs in April alone. That’s compared to roughly 30 per month the year before. Of those, 271 came directly from an early preview of Anthropic’s Claude Mythos model.
The numbers tell a story of sudden acceleration. Engineers didn’t just find memory errors. They uncovered 15-year-old logic flaws, race conditions in IPC, and subtle overflows that had survived years of audits. Some bugs dated back two decades. Others hid in WebAssembly garbage collection or XSLT processing.
AI Agents Meet Decades of Browser Code
Brian Grinstead, Christian Holler, and Frederik Braun detailed the work in a Mozilla Hacks post published May 7. The trio described building an agentic harness on top of existing fuzzing infrastructure. The system generates test cases, runs them, verifies crashes, and produces reproducible reports.
It runs across parallel virtual machines. It integrates with Mozilla’s security triage process. And it swaps models easily. When Claude Mythos Preview became available, the pipeline absorbed it immediately. Results improved dramatically. “It is difficult to overstate how much this dynamic changed for us over a few short months,” the authors wrote.
The bugs span subsystems. One involved an incorrect equality check in the JIT compiler that optimized away initialization of WebAssembly GC structs, creating a fake-object primitive for arbitrary read and write. Another, Bug 2024437, traced to edge cases in the 15-year-old