Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

Scheduled Pinned Locked Moved Uncategorized
18 Posts 6 Posters 86 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • freddy@social.security.plumbingF freddy@social.security.plumbing

    When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

    Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.

    https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

    Link Preview Image
    yoasif@mastodon.socialY This user is from outside of this forum
    yoasif@mastodon.socialY This user is from outside of this forum
    yoasif@mastodon.social
    wrote last edited by
    #2

    @freddy You fixed the bugs with AI too?

    freddy@social.security.plumbingF 1 Reply Last reply
    0
    • yoasif@mastodon.socialY yoasif@mastodon.social

      @freddy You fixed the bugs with AI too?

      freddy@social.security.plumbingF This user is from outside of this forum
      freddy@social.security.plumbingF This user is from outside of this forum
      freddy@social.security.plumbing
      wrote last edited by
      #3

      @yoasif You'll see attachments in some of the bugs. We asked the LLM to propose a patch, but it was real people who were assigned to the bug and they were of course free to pick a different approach.

      As with all patches in Firefox, we need a human author and another human to review the patch. https://firefox-source-docs.mozilla.org/contributing/ai-coding.html

      yoasif@mastodon.socialY 1 Reply Last reply
      0
      • freddy@social.security.plumbingF freddy@social.security.plumbing

        @yoasif You'll see attachments in some of the bugs. We asked the LLM to propose a patch, but it was real people who were assigned to the bug and they were of course free to pick a different approach.

        As with all patches in Firefox, we need a human author and another human to review the patch. https://firefox-source-docs.mozilla.org/contributing/ai-coding.html

        yoasif@mastodon.socialY This user is from outside of this forum
        yoasif@mastodon.socialY This user is from outside of this forum
        yoasif@mastodon.social
        wrote last edited by
        #4

        @freddy You are the ones fixing the bugs, but your comment is pretty ambiguous -- your initial post says the bugs were fixed by AI, and then you say that you need a human author to write and review the patch.

        Which is it - is it a human author or an AI author?

        If it is a human author, can you really say that it was fixed by AI?

        henearxn@chaos.socialH 1 Reply Last reply
        0
        • yoasif@mastodon.socialY yoasif@mastodon.social

          @freddy You are the ones fixing the bugs, but your comment is pretty ambiguous -- your initial post says the bugs were fixed by AI, and then you say that you need a human author to write and review the patch.

          Which is it - is it a human author or an AI author?

          If it is a human author, can you really say that it was fixed by AI?

          henearxn@chaos.socialH This user is from outside of this forum
          henearxn@chaos.socialH This user is from outside of this forum
          henearxn@chaos.social
          wrote last edited by
          #5

          @yoasif @freddy the original post says "using", not "by"?

          yoasif@mastodon.socialY 1 Reply Last reply
          0
          • henearxn@chaos.socialH henearxn@chaos.social

            @yoasif @freddy the original post says "using", not "by"?

            yoasif@mastodon.socialY This user is from outside of this forum
            yoasif@mastodon.socialY This user is from outside of this forum
            yoasif@mastodon.social
            wrote last edited by
            #6

            @HeNeArXn @freddy Touché! I understood that "using" AI gave you the result - the topline here does the same "found and fixed".

            We know the Firefox team didn't find the bugs themselves - that was AI - and the initial post implied (to me) an equivalency between finding and fixing.

            I hoped to understand how much the AI had contributed to fixing the bugs, but it seems like we'll have to see another blog post for that.

            Basically, what does "using AI" mean when fixing these bugs.

            freddy@social.security.plumbingF 1 Reply Last reply
            0
            • yoasif@mastodon.socialY yoasif@mastodon.social

              @HeNeArXn @freddy Touché! I understood that "using" AI gave you the result - the topline here does the same "found and fixed".

              We know the Firefox team didn't find the bugs themselves - that was AI - and the initial post implied (to me) an equivalency between finding and fixing.

              I hoped to understand how much the AI had contributed to fixing the bugs, but it seems like we'll have to see another blog post for that.

              Basically, what does "using AI" mean when fixing these bugs.

              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbing
              wrote last edited by
              #7

              @yoasif @HeNeArXn You can just click the bugs and see the attachments? 🙂

              yoasif@mastodon.socialY 1 Reply Last reply
              0
              • freddy@social.security.plumbingF freddy@social.security.plumbing

                @yoasif @HeNeArXn You can just click the bugs and see the attachments? 🙂

                yoasif@mastodon.socialY This user is from outside of this forum
                yoasif@mastodon.socialY This user is from outside of this forum
                yoasif@mastodon.social
                wrote last edited by
                #8

                @freddy @HeNeArXn The attachments show the result, not the process. People using the tools would be able to give us a better understanding of what is actually happening.

                freddy@social.security.plumbingF 1 Reply Last reply
                0
                • yoasif@mastodon.socialY yoasif@mastodon.social

                  @freddy @HeNeArXn The attachments show the result, not the process. People using the tools would be able to give us a better understanding of what is actually happening.

                  freddy@social.security.plumbingF This user is from outside of this forum
                  freddy@social.security.plumbingF This user is from outside of this forum
                  freddy@social.security.plumbing
                  wrote last edited by
                  #9

                  @yoasif @HeNeArXn Yeah, I don't think we can share the tools but happy to answer questions 🙂

                  1 Reply Last reply
                  0
                  • freddy@social.security.plumbingF freddy@social.security.plumbing

                    When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

                    Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.

                    https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

                    Link Preview Image
                    alesandroortiz@infosec.exchangeA This user is from outside of this forum
                    alesandroortiz@infosec.exchangeA This user is from outside of this forum
                    alesandroortiz@infosec.exchange
                    wrote last edited by
                    #10

                    @freddy Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs.

                    Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP?

                    (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)

                    freddy@social.security.plumbingF 1 Reply Last reply
                    0
                    • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

                      @freddy Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs.

                      Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP?

                      (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)

                      freddy@social.security.plumbingF This user is from outside of this forum
                      freddy@social.security.plumbingF This user is from outside of this forum
                      freddy@social.security.plumbing
                      wrote last edited by
                      #11

                      @AlesandroOrtiz https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html 🙂

                      alesandroortiz@infosec.exchangeA 1 Reply Last reply
                      0
                      • freddy@social.security.plumbingF freddy@social.security.plumbing

                        @AlesandroOrtiz https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html 🙂

                        alesandroortiz@infosec.exchangeA This user is from outside of this forum
                        alesandroortiz@infosec.exchangeA This user is from outside of this forum
                        alesandroortiz@infosec.exchange
                        wrote last edited by
                        #12

                        @freddy Ah, forgot about those changes. (It's been a _very long_ 2 months.)

                        Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated.

                        Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).

                        freddy@social.security.plumbingF 1 Reply Last reply
                        0
                        • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

                          @freddy Ah, forgot about those changes. (It's been a _very long_ 2 months.)

                          Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated.

                          Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).

                          freddy@social.security.plumbingF This user is from outside of this forum
                          freddy@social.security.plumbingF This user is from outside of this forum
                          freddy@social.security.plumbing
                          wrote last edited by
                          #13

                          @AlesandroOrtiz yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… 🤷‍♂️

                          alesandroortiz@infosec.exchangeA 1 Reply Last reply
                          0
                          • freddy@social.security.plumbingF freddy@social.security.plumbing

                            @AlesandroOrtiz yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… 🤷‍♂️

                            alesandroortiz@infosec.exchangeA This user is from outside of this forum
                            alesandroortiz@infosec.exchangeA This user is from outside of this forum
                            alesandroortiz@infosec.exchange
                            wrote last edited by
                            #14

                            @freddy Less? That's very surprising.

                            Thought it would continue increasing despite *gestures wildly* everything.

                            skryking@infosec.exchangeS 1 Reply Last reply
                            0
                            • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

                              @freddy Less? That's very surprising.

                              Thought it would continue increasing despite *gestures wildly* everything.

                              skryking@infosec.exchangeS This user is from outside of this forum
                              skryking@infosec.exchangeS This user is from outside of this forum
                              skryking@infosec.exchange
                              wrote last edited by
                              #15

                              @AlesandroOrtiz @freddy I would expect to see a really big surge initially and then tail off unless there's some big step forward in tooling, be it LLM/ML related or other...then tail off again after each initial burst.

                              freddy@social.security.plumbingF 1 Reply Last reply
                              0
                              • skryking@infosec.exchangeS skryking@infosec.exchange

                                @AlesandroOrtiz @freddy I would expect to see a really big surge initially and then tail off unless there's some big step forward in tooling, be it LLM/ML related or other...then tail off again after each initial burst.

                                freddy@social.security.plumbingF This user is from outside of this forum
                                freddy@social.security.plumbingF This user is from outside of this forum
                                freddy@social.security.plumbing
                                wrote last edited by
                                #16

                                @skryking @AlesandroOrtiz less valid from bug bounty, given we found them first? 🙂 might change over time of course

                                1 Reply Last reply
                                0
                                • freddy@social.security.plumbingF This user is from outside of this forum
                                  freddy@social.security.plumbingF This user is from outside of this forum
                                  freddy@social.security.plumbing
                                  wrote last edited by
                                  #17

                                  RE: https://social.security.plumbing/@freddy/116534213887768480

                                  @enigmatico

                                  1 Reply Last reply
                                  0
                                  • freddy@social.security.plumbingF freddy@social.security.plumbing

                                    When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

                                    Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.

                                    https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

                                    Link Preview Image
                                    endareth@disobey.netE This user is from outside of this forum
                                    endareth@disobey.netE This user is from outside of this forum
                                    endareth@disobey.net
                                    wrote last edited by
                                    #18

                                    @freddy Curious exactly how many critical/high #Firefox bugs were reported by #Mythos, vs how many were confirmed/accepted as such by your team?

                                    1 Reply Last reply
                                    1
                                    0
                                    • R relay@relay.mycrowd.ca shared this topic
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups