Firefox fixed more security bugs in April 2026 than in the prior 15 months combined, per Mozilla's Alex Albert. Anthropic's Claude Mythos Preview model powered the triage and patch pipeline.
Key facts
- April 2026 fixed more security bugs than 15 prior months combined.
- Claude Mythos Preview by Anthropic powered the effort.
- Mozilla engineer Alex Albert disclosed the result on X.
- 15-month baseline: January 2025 through March 2026.
- Mozilla did not disclose absolute bug counts.
Alex Albert, a Mozilla engineer, reported on X that the Firefox team fixed more security bugs in April 2026 than in the previous 15 months combined. The work was powered by Anthropic's Claude Mythos Preview model, which was used for vulnerability triage and patch generation [According to @alexalbert__].
The 15-month baseline spans January 2025 through March 2026, meaning April alone exceeded that cumulative total. Mozilla did not disclose the absolute number of bugs fixed, nor the precise version of Claude Mythos Preview used. The model, released in early 2026, is Anthropic's most advanced code-generation system, trained on a large corpus of security advisories and exploit code.
This accelerated cadence suggests that LLMs can meaningfully reduce the mean-time-to-fix for security vulnerabilities, especially in large, legacy codebases like Firefox. Mozilla has not yet published a post-mortem or formal evaluation of the experiment, but the raw outcome — a 15-month backlog cleared in 30 days — is statistically striking.
The result aligns with broader trends in AI-assisted security: in March 2026, Google reported that Gemini 2.0 Pro helped Android security teams close 40% more CVEs in Q1 2026 vs. Q4 2025. Mozilla's outcome, if replicable, signals that AI-assisted vulnerability management is moving from proof-of-concept to production impact.
What to Watch

Watch for Mozilla to release a formal blog post or paper detailing the workflow, bug counts, and false-positive rates. The key metric is whether the April cadence holds in May 2026 — a single-month spike could reflect a backlog of low-hanging bugs, while sustained throughput would validate the approach at scale. Also track whether Mozilla open-sources the prompt templates or triage pipeline for community reuse.
What to watch
Watch for Mozilla's formal post-mortem or paper detailing workflow, bug counts, and false-positive rates. The key metric is whether the April cadence holds in May 2026 — sustained throughput would validate AI-assisted security at scale. Also track whether Mozilla open-sources the triage pipeline.









