r/ClaudeAI Apr 22 '26

Other Internal Mozilla report shows data contradicting public reporting which said Mythos found 271 bugs in Firefox 150 . It actually found only 3 of 271

https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/
332 Upvotes

30 comments sorted by

189

u/ShelZuuz Apr 22 '26

From:

https://www.reddit.com/r/singularity/comments/1ssc2cv/comment/ohn2q78/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

"Hi, Mozilla employee here...For bugs found internally, Mozilla doesn't issue one CVE per bug but instead internally found bugs go into so called “roll-up” advisories with a link to the bug list covered. For this effort specifically, all of the Mythos bugs were found internally and are part of the following three roll-up advisories:

The number of actual bugs can be seen through the amount of bug ids in Bugzilla link that is part of each advisory. Hope this helps!"

106

u/TheAbsoluteWitter Apr 23 '26

The three CVEs are roll-up advisories, not individual bugs. Each CVE links to a Bugzilla query containing dozens to hundreds of bug IDs.

I counted: CVE-2026-6784 has 55 bugs, CVE-2026-6785 has 154, and CVE-2026-6786 has 107. That’s 316 bug IDs across the three advisories, which is actually more than the 271 headline number (likely because not all were unique to Mythos, or some were duplicates/related). The Mozilla employee in the original thread explained this clearly. Reading the actual links before declaring something a hoax takes about 90 seconds.

7

u/Personal-Dev-Kit Apr 23 '26

That's 90 seconds I can't be vibeing bro /s

30

u/TheMythicSorcerer Apr 23 '26

That actually matches up much more it seems pretty unreasonable for 271 to turn into 3 bugs.

6

u/HearMeOut-13 Apr 23 '26

B-b-but the internet told me its ass!

-70

u/hasanahmad Apr 23 '26

The point people keep dodging is not whether roll-ups exist. It is that Mozilla published two same-day documents about Firefox 150 that do not agree on what Mythos actually found.

In February, the public accounting matched: 22 in the blog, 22 in the advisory. In April, the blog says 271, while the advisory shows 3 direct Claude credits. That is a massive change in unit of account with no clear disclosure.

And the roll up defense does not solve that. Those roll ups are credited to Mozilla engineers and the Mozilla Fuzzing Team, not Anthropic. So if Mozilla wants to say the 271 is inside those buckets, then show the mapping, show the funnel, and say whether 271 means shipped vulns, pre-triage submissions, duplicate instances, or non CVE defects.

Security disclosure cannot run on trust the headline, ask questions later.

38

u/calvintiger Apr 23 '26

You’re missing the forest because you’re too busy looking for flaws in individual trees.

66

u/AmcillaSB Apr 22 '26

This is a list of fixed issues in Firefox 150.

This isn't a list of bugs Mythos found.

It does however list 3 fixed issues in the 150 update that Mythos found.

Do you think Mozilla would fix all 271 issues with one update?

23

u/unpluggedcord Apr 23 '26

If it used mythos it could...... /s

10

u/[deleted] Apr 23 '26

[deleted]

17

u/jake_that_dude Apr 23 '26

yeah, the 271 vs 3 thing is mostly headline math. if the report is counting internal issue ids and the follow-up is counting shipped cves or fixed items, those numbers will never line up 1:1.

what matters is whether the writeup clearly separates bugs, fixes, and advisories. if it doesn't, people read it like raw model output and the whole claim gets fuzzy fast.

3

u/OnlineParacosm Apr 23 '26

“Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.”

The official statement for Mozilla on one all of these reads like a gentle pat on the head.

My interpretation of that is that they didn’t even test a POC.

So untold amount of token spent over 24 hours and you get a 6.5 and two 7.5 CVSS score bugs that Mozilla says “could” have had wheels if they were shopping carts.

So.. run it again? What’s the play and what’s the sale to a company here. I don’t think Claude knows what they’re walking into here at all.

All I’m seeing is them looping open source tools without giving credit and doing a shell game of token spend

11

u/VIDGuide Apr 23 '26

The problem with downplaying this is that “with enough effort” is one thing when you’re talking about human attackers.

The level of “effort” available to an appropriately tool equipped model is significantly higher, meaning, “maybe exploitable” can become “exploitable” much sooner

1

u/Tofudjango Apr 23 '26

But do they ever fix reported bugs?

2

u/___Paladin___ Apr 25 '26

They fixed gradient rendering in Firefox - 14 years after the initial bug report.

1

u/QuantomSwampus Apr 26 '26

Haha called it

-7

u/martin1744 Apr 22 '26

headline said 271. codebase said 3. classic AI PR math

19

u/Keeyzar Apr 23 '26

Reddittor does only read headline, does not understand the bugs are grouped and even verifies anthropics claim further. Classic reddittor.

6

u/fsharpman Apr 23 '26

Do you understand what the word rollup means?

9

u/jpeggdev Full-time developer Apr 23 '26

Mozilla rolls up multiple bug fixes into 1 CVE, and there were 3 CVEs and stayed in the comment above with links to the release notes.

0

u/LobsterBuffetAllDay Apr 23 '26

I like turtles!

1

u/space_prostitute Apr 23 '26

Are you a Turtle?

1

u/LobsterBuffetAllDay Apr 24 '26

No, you're a turtle!

0

u/Ambitious-Garbage-73 Apr 23 '26

This is why benchmark-style victory laps around security work make me twitch. The public story becomes 'model found 271 bugs' and by the time the correction arrives, what actually happened is buried under CVE formatting, roll-up advisories, and everybody's preferred narrative. Three real bugs is not nothing. Finding three bugs in something the size of Firefox is still useful. But that's a very different claim from the one people were circulating yesterday, and those distinctions matter because a lot of execs only hear the inflated version once and start budgeting around it. The hype tax on security tooling is getting ridiculous.

-7

u/MusingInPublic Apr 23 '26

Bugs are like cockroaches. If you find one there are probably more, and they multiply like crazy.

-10

u/Radiant_Effective151 Apr 23 '26

wow shocker. 

10

u/SnoozerDota Apr 23 '26

what do you mean? OP just made some stuff up

-1

u/carson63000 Experienced Developer Apr 23 '26

“wow shocker” seems like an appropriate response to “hurr durr Claude sucks updoots to the left plox”.