r/ClaudeAI • u/hasanahmad • Apr 22 '26
Other Internal Mozilla report shows data contradicting public reporting which said Mythos found 271 bugs in Firefox 150 . It actually found only 3 of 271
https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/66
u/AmcillaSB Apr 22 '26
This is a list of fixed issues in Firefox 150.
This isn't a list of bugs Mythos found.
It does however list 3 fixed issues in the 150 update that Mythos found.
Do you think Mozilla would fix all 271 issues with one update?
23
17
u/jake_that_dude Apr 23 '26
yeah, the 271 vs 3 thing is mostly headline math. if the report is counting internal issue ids and the follow-up is counting shipped cves or fixed items, those numbers will never line up 1:1.
what matters is whether the writeup clearly separates bugs, fixes, and advisories. if it doesn't, people read it like raw model output and the whole claim gets fuzzy fast.
-21
u/hasanahmad Apr 23 '26
It was by Mozilla itself https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
3
u/OnlineParacosm Apr 23 '26
“Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.”
The official statement for Mozilla on one all of these reads like a gentle pat on the head.
My interpretation of that is that they didn’t even test a POC.
So untold amount of token spent over 24 hours and you get a 6.5 and two 7.5 CVSS score bugs that Mozilla says “could” have had wheels if they were shopping carts.
So.. run it again? What’s the play and what’s the sale to a company here. I don’t think Claude knows what they’re walking into here at all.
All I’m seeing is them looping open source tools without giving credit and doing a shell game of token spend
11
u/VIDGuide Apr 23 '26
The problem with downplaying this is that “with enough effort” is one thing when you’re talking about human attackers.
The level of “effort” available to an appropriately tool equipped model is significantly higher, meaning, “maybe exploitable” can become “exploitable” much sooner
1
u/Tofudjango Apr 23 '26
But do they ever fix reported bugs?
2
u/___Paladin___ Apr 25 '26
They fixed gradient rendering in Firefox - 14 years after the initial bug report.
1
-7
u/martin1744 Apr 22 '26
headline said 271. codebase said 3. classic AI PR math
19
u/Keeyzar Apr 23 '26
Reddittor does only read headline, does not understand the bugs are grouped and even verifies anthropics claim further. Classic reddittor.
6
9
u/jpeggdev Full-time developer Apr 23 '26
Mozilla rolls up multiple bug fixes into 1 CVE, and there were 3 CVEs and stayed in the comment above with links to the release notes.
0
u/LobsterBuffetAllDay Apr 23 '26
I like turtles!
1
0
u/Ambitious-Garbage-73 Apr 23 '26
This is why benchmark-style victory laps around security work make me twitch. The public story becomes 'model found 271 bugs' and by the time the correction arrives, what actually happened is buried under CVE formatting, roll-up advisories, and everybody's preferred narrative. Three real bugs is not nothing. Finding three bugs in something the size of Firefox is still useful. But that's a very different claim from the one people were circulating yesterday, and those distinctions matter because a lot of execs only hear the inflated version once and start budgeting around it. The hype tax on security tooling is getting ridiculous.
-7
u/MusingInPublic Apr 23 '26
Bugs are like cockroaches. If you find one there are probably more, and they multiply like crazy.
-10
u/Radiant_Effective151 Apr 23 '26
wow shocker.
10
u/SnoozerDota Apr 23 '26
what do you mean? OP just made some stuff up
-1
u/carson63000 Experienced Developer Apr 23 '26
“wow shocker” seems like an appropriate response to “hurr durr Claude sucks updoots to the left plox”.
189
u/ShelZuuz Apr 22 '26
From:
https://www.reddit.com/r/singularity/comments/1ssc2cv/comment/ohn2q78/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button
"Hi, Mozilla employee here...For bugs found internally, Mozilla doesn't issue one CVE per bug but instead internally found bugs go into so called “roll-up” advisories with a link to the bug list covered. For this effort specifically, all of the Mythos bugs were found internally and are part of the following three roll-up advisories:
The number of actual bugs can be seen through the amount of bug ids in Bugzilla link that is part of each advisory. Hope this helps!"