Close Menu
    What's Hot

    The train that derailed a private equity titan

    Celestica Stock: The Market Just Started To Agree, And Q2 Isn’t Priced Yet (NYSE:CLS)

    F1 driver market: Red Bull getting calls from ‘good drivers’ says Laurent Mekies but optimistic on Max Verstappen stay | F1 News

    Facebook X (Twitter) Instagram
    Trending
    • The train that derailed a private equity titan
    • Celestica Stock: The Market Just Started To Agree, And Q2 Isn’t Priced Yet (NYSE:CLS)
    • F1 driver market: Red Bull getting calls from ‘good drivers’ says Laurent Mekies but optimistic on Max Verstappen stay | F1 News
    • New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
    • Saudis Reach Deal With U.S. That Could Let Them Enrich Nuclear Fuel
    • Who will win the war of neo-mercantilists?
    • It’s Monday in Paris. Time to Wind the Clocks.
    • Gen Z’s viral advice to a first-time 9-to-5 worker is an indictment of office culture—but also surprisingly practical
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model

    adminBy adminMarch 7, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 07, 2026Browser Security / Artificial Intelligence

    Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model

    Anthropic on Friday said it discovered 22 new security vulnerabilities in the Firefox web browser as part of a security partnership with Mozilla.

    Of these, 14 have been classified as high, seven have been classified as moderate, and one has been rated low in severity. The issues were addressed in Firefox 148, released late last month. The vulnerabilities were identified over a two-week period in January 2026.

    The artificial intelligence (AI) company said the number of high-severity bugs identified by its Claude Opus 4.6 large language model (LLM) represents “almost a fifth” of all high-severity vulnerabilities that were patched in Firefox in 2025.

    Anthropic said the LLM detected a use-after-free bug in the browser’s JavaScript after “just” 20 minutes of exploration, which was then validated by a human researcher in a virtualized environment to rule out the possibility of a false positive.

    Cybersecurity

    “By the end of this effort, we had scanned nearly 6,000 C++ files and submitted a total of 112 unique reports, including the high- and moderate-severity vulnerabilities mentioned above,” the company said. “Most issues have been fixed in Firefox 148, with the remainder to be fixed in upcoming releases.”

    The AI upstart said it also fed its Claude model access to the entire list of vulnerabilities submitted to Mozilla and tasked the AI tool with developing a practical exploit for them.

    Despite carrying out the test several hundred times and spending about $4,000 in API credits, the company said Claude Opus 4.6 was able to turn the security defect into an exploit only in two cases.

    This behavior, the company added, signaled two important aspects: the cost of identifying vulnerabilities is cheaper than creating an exploit for them, and the model is better at finding issues than at exploiting them.

    “However, the fact that Claude could succeed at automatically developing a crude browser exploit, even if only in a few cases, is concerning,” Anthropic emphasized, adding the exploits only worked within the confines of its testing environment, which has had some security features like sandboxing intentionally stripped off.

    A crucial component incorporated into the process is a task verifier to determine if the exploit actually works, giving the tool real-time feedback as it explores the codebase in question and allowing it to iterate its results until a successful exploit is devised.

    One such exploit Claude wrote was for CVE-2026-2796 (CVSS score: 9.8), which has been described as a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component.

    The disclosure comes weeks after the company released Claude Code Security in a limited research preview as a way to fix vulnerabilities using an AI agent.

    Cybersecurity

    “We can’t guarantee that all agent-generated patches that pass these tests are good enough to merge immediately,” Anthropic said. “But task verifiers give us increased confidence that the produced patch will fix the specific vulnerability while preserving program functionality—and therefore achieve what’s considered to be the minimum requirement for a plausible patch.”

    Mozilla, in a coordinated announcement, said the AI-assisted approach has discovered 90 other bugs, most of which have been fixed. These consisted of assertion failures that overlapped with issues traditionally found through fuzzing and distinct classes of logic errors that the fuzzers failed to catch.

    “The scale of findings reflects the power of combining rigorous engineering with new analysis tools for continuous improvement,” the browser maker said. “We view this as clear evidence that large-scale, AI-assisted analysis is a powerful new addition to security engineers’ toolbox.”

    Anthropic Claude finds Firefox model Opus Vulnerabilities
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | One President’s Whim. A World in Crisis.
    Next Article Best Mid Layer for Hiking, Backpacking, and Travel (2026)
    admin
    • Website

    Related Posts

    New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

    July 22, 2026

    N-day is Becoming N-Hour. Patching Faster Won’t Save You.

    July 22, 2026

    LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

    July 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    The train that derailed a private equity titan

    Celestica Stock: The Market Just Started To Agree, And Q2 Isn’t Priced Yet (NYSE:CLS)

    F1 driver market: Red Bull getting calls from ‘good drivers’ says Laurent Mekies but optimistic on Max Verstappen stay | F1 News

    New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by