Anthropic's Frontier Red Team used Claude to perform AI-assisted vulnerability detection on Firefox's codebase, discovering 14 high-severity bugs and issuing 22 CVEs, all of which have been fixed in Firefox 148. The team also found 90 additional lower-severity bugs. Unlike typical AI bug reports, each submission included minimal reproducible test cases, enabling Mozilla engineers to verify and fix issues quickly. The collaboration highlights AI-assisted analysis as a powerful new security tool, capable of uncovering logic errors that traditional fuzzing missed. Mozilla is now integrating similar AI-assisted analysis into its internal security workflows.
Table of contents
An emerging technique, pressure-tested by Firefox engineersBuilding in the open for usersSort: