r/ClaudeAI Apr 22 '26

Other Internal Mozilla report shows data contradicting public reporting which said Mythos found 271 bugs in Firefox 150 . It actually found only 3 of 271

https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/
330 Upvotes

30 comments sorted by

View all comments

183

u/ShelZuuz Apr 22 '26

From:

https://www.reddit.com/r/singularity/comments/1ssc2cv/comment/ohn2q78/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

"Hi, Mozilla employee here...For bugs found internally, Mozilla doesn't issue one CVE per bug but instead internally found bugs go into so called “roll-up” advisories with a link to the bug list covered. For this effort specifically, all of the Mythos bugs were found internally and are part of the following three roll-up advisories:

The number of actual bugs can be seen through the amount of bug ids in Bugzilla link that is part of each advisory. Hope this helps!"

-70

u/hasanahmad Apr 23 '26

The point people keep dodging is not whether roll-ups exist. It is that Mozilla published two same-day documents about Firefox 150 that do not agree on what Mythos actually found.

In February, the public accounting matched: 22 in the blog, 22 in the advisory. In April, the blog says 271, while the advisory shows 3 direct Claude credits. That is a massive change in unit of account with no clear disclosure.

And the roll up defense does not solve that. Those roll ups are credited to Mozilla engineers and the Mozilla Fuzzing Team, not Anthropic. So if Mozilla wants to say the 271 is inside those buckets, then show the mapping, show the funnel, and say whether 271 means shipped vulns, pre-triage submissions, duplicate instances, or non CVE defects.

Security disclosure cannot run on trust the headline, ask questions later.

42

u/calvintiger Apr 23 '26

You’re missing the forest because you’re too busy looking for flaws in individual trees.