Anthropic's Claude AI Can Convert Software Patches Into Exploits Within Hours
Anthropic's Claude Mythos Preview model converts public software patches into working exploits within hours. The model completed its first Firefox exploit in under an hour and produced a Windows kernel vulnerability proof-of-concept in 31 minutes. It generated eight exploit chains escalating to SYSTEM-level control for approximately $15,700 in API credits. Tests used vulnerabilities patched in January and February 2026.
Claude Mythos exploit generation
▪Anthropic's public Claude models were able to develop exploits when safeguards were disabled, with lower success rates than Claude Mythos Preview.
▪Anthropic selected the tested vulnerabilities because they were disclosed after the Claude Mythos Preview model's knowledge cutoff.
▪Anthropic's Claude Mythos Preview model completed its first Firefox exploit in under an hour.
▪Anthropic's Claude Mythos Preview model can turn public software patches into working exploits within hours.
Windows kernel vulnerability testing
▪Anthropic's Claude Mythos Preview model produced proof-of-concept crashes for 13 of 14 Windows vulnerabilities that Microsoft had rated as 'Exploitation Less Likely' or 'Exploitation Unlikely'.
▪Anthropic's Claude Mythos Preview model built eight exploit chains that escalated a low-privilege user to SYSTEM-level control in Windows.
▪The eight Windows exploit chains generated by Anthropic's Claude Mythos Preview model cost approximately $15,700 in API credits, with an average cost of roughly $2,000 per exploit.
▪Anthropic's Claude Mythos Preview model generated proof-of-concept crashes for 18 of 21 Windows kernel vulnerabilities, all completed within six hours.
▪Anthropic's Claude Mythos Preview model produced a proof-of-concept exploit for a Windows kernel vulnerability in 31 minutes.
▪Anthropic's red team tested the Claude Mythos Preview model against recently disclosed vulnerabilities in Mozilla Firefox and the Microsoft Windows kernel that had been patched in January and February 2026.
Firefox SpiderMonkey testing
▪The stable Firefox release containing the fix for the first exploit generated by Claude Mythos Preview was still 18 days away when the exploit was completed.
▪Anthropic's Claude Mythos Preview model generated working proof-of-concept crashes for 14 of 18 Firefox SpiderMonkey patches.
▪The patches in Anthropic's Firefox test had a median gap of 19 days before release.
▪Anthropic's Firefox test provided the Claude Mythos Preview model with the public code diff, component name, Mozilla's severity rating, and two builds of SpiderMonkey (one vulnerable and one patched).
▪Anthropic's Claude Mythos Preview model turned eight Firefox SpiderMonkey proof-of-concept crashes into full exploits capable of arbitrary code execution.
Patch deployment timelines
▪A 2020 Mandiant analysis found that 16 of 25 N-day vulnerabilities took a month or more to exploit.
▪WannaCry appeared 59 days after Microsoft released the MS17-010 patch in 2017.
▪Windows Autopatch typically takes seven days before a patch is shared to 90% of enrolled devices, with forced reboot happening on day 11.
▪Anthropic's Claude Mythos Preview model completed all eight full Windows exploit chains before the seven-day Windows Autopatch reference point.
▪A public exploit for Citrix Bleed in 2023 took about two weeks to develop.
Story comments
Loading comments…