Mozilla

Maker of Firefox; long-running open-source browser vendor. Key relevance to this KB: defender-side experience with AI-assisted vulnerability discovery in critical internet-exposed software.

Key positions on AI security

  • Frontier AI has, in Mozilla’s experience, closed the historic gap between machine-discoverable and human-discoverable bugs, and that this is structurally pro-defender. [[2026-04-21-firefox-mythos-zero-days]]
  • Believes the defects in human-designed software are finite, and that future AI is unlikely to surface entirely new vulnerability classes that defy human comprehension — provided codebases remain human-comprehensible. [[2026-04-21-firefox-mythos-zero-days]]
  • Flags a load-bearing caveat: if AI-assisted development produces code humans cannot reason about, bug complexity may scale with discovery capability, undoing the defender gain. Calls human-comprehensibility “an essential property to maintain.” [[2026-04-21-firefox-mythos-zero-days]]

Empirical record (Firefox)

  • Firefox 148 — 22 security-sensitive bugs fixed from an Anthropic Opus 4.6 scan. [[2026-04-21-firefox-mythos-zero-days]]
  • Firefox 150 — 271 vulnerabilities fixed from Claude Mythos Preview initial evaluation. [[2026-04-21-firefox-mythos-zero-days]]

See also