Mozilla says AI-assisted Mythos found 271 Firefox vulnerabilities with few false positives

by

Mozilla said on Thursday that its Mythos AI-assisted vulnerability discovery effort turned up 271 Firefox security bugs, including 180 rated sec-high, 80 sec-moderate and 11 sec-low, as the company defended the approach against criticism about false positives.

KEY FACTS

  • Total findings 271 vulnerabilities were identified through Mythos.
  • Severity mix 180 were rated sec-high, 80 sec-moderate and 11 sec-low.
  • Reporting practice Mozilla said internally found bugs are often bundled into rollup patches, not filed as individual CVEs.
  • Context Critics had questioned the results because no CVE designations were obtained for the 271 bugs.

The company said Bugzilla reports for these rollups are usually hidden for several months after fixes are released to protect users who patch slowly. Mozilla has now revealed a dozen of those reports, which the company said should help explain how the findings were handled.

Of the vulnerabilities, the sec-high issues were described as exploitable through normal user behavior, such as visiting a web page. The higher sec-critical rating is reserved for zero-days, according to the company’s classification system.

Mozilla also argued that the disclosure was meant to show more detail about the technique and to encourage further discussion. It said the team is not trying to promote any specific model provider or company.

WHY IT MATTERS

The disclosure adds concrete numbers to a debate over whether AI-assisted tools can reliably find security flaws without producing too many false alarms. It also shows how browser makers may choose to disclose internal vulnerabilities in rollups rather than as individual CVEs.