Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

Scheduled Pinned Locked Moved Uncategorized
18 Posts 6 Posters 86 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • freddy@social.security.plumbingF freddy@social.security.plumbing

    @yoasif @HeNeArXn You can just click the bugs and see the attachments? πŸ™‚

    yoasif@mastodon.socialY This user is from outside of this forum
    yoasif@mastodon.socialY This user is from outside of this forum
    yoasif@mastodon.social
    wrote last edited by
    #8

    @freddy @HeNeArXn The attachments show the result, not the process. People using the tools would be able to give us a better understanding of what is actually happening.

    freddy@social.security.plumbingF 1 Reply Last reply
    0
    • yoasif@mastodon.socialY yoasif@mastodon.social

      @freddy @HeNeArXn The attachments show the result, not the process. People using the tools would be able to give us a better understanding of what is actually happening.

      freddy@social.security.plumbingF This user is from outside of this forum
      freddy@social.security.plumbingF This user is from outside of this forum
      freddy@social.security.plumbing
      wrote last edited by
      #9

      @yoasif @HeNeArXn Yeah, I don't think we can share the tools but happy to answer questions πŸ™‚

      1 Reply Last reply
      0
      • freddy@social.security.plumbingF freddy@social.security.plumbing

        When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

        Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.

        https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

        Link Preview Image
        alesandroortiz@infosec.exchangeA This user is from outside of this forum
        alesandroortiz@infosec.exchangeA This user is from outside of this forum
        alesandroortiz@infosec.exchange
        wrote last edited by
        #10

        @freddy Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs.

        Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP?

        (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)

        freddy@social.security.plumbingF 1 Reply Last reply
        0
        • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

          @freddy Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs.

          Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP?

          (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)

          freddy@social.security.plumbingF This user is from outside of this forum
          freddy@social.security.plumbingF This user is from outside of this forum
          freddy@social.security.plumbing
          wrote last edited by
          #11

          @AlesandroOrtiz https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html πŸ™‚

          alesandroortiz@infosec.exchangeA 1 Reply Last reply
          0
          • freddy@social.security.plumbingF freddy@social.security.plumbing

            @AlesandroOrtiz https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html πŸ™‚

            alesandroortiz@infosec.exchangeA This user is from outside of this forum
            alesandroortiz@infosec.exchangeA This user is from outside of this forum
            alesandroortiz@infosec.exchange
            wrote last edited by
            #12

            @freddy Ah, forgot about those changes. (It's been a _very long_ 2 months.)

            Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated.

            Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).

            freddy@social.security.plumbingF 1 Reply Last reply
            0
            • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

              @freddy Ah, forgot about those changes. (It's been a _very long_ 2 months.)

              Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated.

              Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).

              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbing
              wrote last edited by
              #13

              @AlesandroOrtiz yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… πŸ€·β€β™‚οΈ

              alesandroortiz@infosec.exchangeA 1 Reply Last reply
              0
              • freddy@social.security.plumbingF freddy@social.security.plumbing

                @AlesandroOrtiz yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… πŸ€·β€β™‚οΈ

                alesandroortiz@infosec.exchangeA This user is from outside of this forum
                alesandroortiz@infosec.exchangeA This user is from outside of this forum
                alesandroortiz@infosec.exchange
                wrote last edited by
                #14

                @freddy Less? That's very surprising.

                Thought it would continue increasing despite *gestures wildly* everything.

                skryking@infosec.exchangeS 1 Reply Last reply
                0
                • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

                  @freddy Less? That's very surprising.

                  Thought it would continue increasing despite *gestures wildly* everything.

                  skryking@infosec.exchangeS This user is from outside of this forum
                  skryking@infosec.exchangeS This user is from outside of this forum
                  skryking@infosec.exchange
                  wrote last edited by
                  #15

                  @AlesandroOrtiz @freddy I would expect to see a really big surge initially and then tail off unless there's some big step forward in tooling, be it LLM/ML related or other...then tail off again after each initial burst.

                  freddy@social.security.plumbingF 1 Reply Last reply
                  0
                  • skryking@infosec.exchangeS skryking@infosec.exchange

                    @AlesandroOrtiz @freddy I would expect to see a really big surge initially and then tail off unless there's some big step forward in tooling, be it LLM/ML related or other...then tail off again after each initial burst.

                    freddy@social.security.plumbingF This user is from outside of this forum
                    freddy@social.security.plumbingF This user is from outside of this forum
                    freddy@social.security.plumbing
                    wrote last edited by
                    #16

                    @skryking @AlesandroOrtiz less valid from bug bounty, given we found them first? πŸ™‚ might change over time of course

                    1 Reply Last reply
                    0
                    • freddy@social.security.plumbingF This user is from outside of this forum
                      freddy@social.security.plumbingF This user is from outside of this forum
                      freddy@social.security.plumbing
                      wrote last edited by
                      #17

                      RE: https://social.security.plumbing/@freddy/116534213887768480

                      @enigmatico

                      1 Reply Last reply
                      0
                      • freddy@social.security.plumbingF freddy@social.security.plumbing

                        When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs?

                        Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found.

                        https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

                        Link Preview Image
                        endareth@disobey.netE This user is from outside of this forum
                        endareth@disobey.netE This user is from outside of this forum
                        endareth@disobey.net
                        wrote last edited by
                        #18

                        @freddy Curious exactly how many critical/high #Firefox bugs were reported by #Mythos, vs how many were confirmed/accepted as such by your team?

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.mycrowd.ca shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups