Artificial intelligence doesn’t just write code or answer questions anymore. Now it also finds security flaws in real software. And it does it very quickly.
A recent experiment between Anthropic and Mozilla revealed something rather surprising: the Claude Opus 4.6 AI model was able to detect 22 browser vulnerabilities Firefox in just two weeks, including 14 failures that are considered very serious.
The result not only demonstrates the potential of artificial intelligence in the field of computer security. It also raises an awkward question: If AI can find vulnerabilities so quickly… what happens when it can exploit them too?
Claude, the artificial intelligence that tested Firefox
The experiment was conducted by Anthropic’s security team in collaboration with Mozilla developers. For the test they used Close work 4.6is one of the company’s most advanced models, and they’ve provided it to analyze the code of the Firefox browser.
Over the course of two weeks, the system scanned thousands of project files, including critical components such as the JavaScript engine, for anomalous behavior and potential security flaws.
The result was stunning:
• 22 confirmed vulnerabilities
• 14 errors of high severity
• 100+ additional minor bugs
Many of these issues have already been fixed in Firefox 148, the latest version of the browser.
Interestingly, the first failure was detected by the AI less than 20 minutes after the start of the analysis.
Why this experiment is important for digital security
Finding vulnerabilities in complex software is a process that usually takes weeks or months. Security researchers have to go through millions of lines of code and test different scenarios to find bugs.
AI can completely change this dynamic.
In the case of Firefox, Claude found more critical bugs in two weeks than outside researchers typically report in months.
This means that AI tools can become a new line of defense to protect the software used by millions of people. In other words:
- AI could be the new antivirus of software development.
- But artificial intelligence still has its limits
- While the experiment was impressive, it also showed that AI still can’t do everything.
The Anthropic team tried to get Claude not only to discover vulnerabilities, but also to create functional exploits (attacks that exploit these flaws). To achieve this, they spent about $4,000 in API credits, but received only two functional proofs of concept.
This has two sides:
Good news: Developers can find bugs before attackers exploit them. The bad news: Hackers can also use AI to massively search for vulnerabilities.
And here the technology race becomes much more intense.
The experiment between Anthropic and Mozilla is a clear sign of where the technology industry is headed. Artificial intelligence no longer just helps you write code: it can also analyze complex systems and find critical bugs in a matter of hours.
The fact that artificial intelligence has discovered 22 vulnerabilities in Firefox in just two weeks shows that we are entering a new era of cyber security.
An era where machines help protect software… but can also become a favorite tool of attackers.
CATEGORIES:
Applications, security, software
Get news, analysis and geek content straight to your inbox.

