The Mozilla Foundation collaborated with Anthropic to utilize the Claude AI model to uncover 22 security vulnerabilities in the Firefox browser within two weeks, including 14 high-risk flaws, accounting for 20% of the total high-risk vulnerabilities fixed throughout 2025. These vulnerabilities have been addressed in Firefox version 148.0. Claude AI first analyzed Firefox's JavaScript engine, identifying a memory vulnerability within 20 minutes and swiftly pinpointing over 50 crash inputs. Ultimately, the AI scanned nearly 6,000 C++ files and submitted 112 vulnerability reports. Tests revealed that the cost of identifying vulnerabilities using AI was significantly lower than the cost of creating real attacks, and the generated attack code was only effective in specific test environments.
