Anthropic has restricted access to its new AI model, Mythos, after testing revealed it could autonomously identify and exploit high-severity vulnerabilities in major operating systems and web browsers. Simultaneously, University of Washington researchers found that current agentic web browsers possess security risks, including the potential to bypass fundamental “same-origin” web protections.
Anthropic’s Mythos Model and the Project Glasswing Initiative
Anthropic has taken the unusual step of withholding its latest model, Mythos, from public release due to its potent cybersecurity capabilities. Unlike previous iterations, Mythos has demonstrated an ability to chain together multiple vulnerabilities to execute complex attacks that were previously considered achievable only by expert human professionals. In internal testing, the model successfully identified zero-day vulnerabilities in every major operating system and web browser, some of which had remained undiscovered for decades.
To mitigate the risk of these capabilities being used by hostile actors, Anthropic is launching Singularityhub. This initiative provides select technology companies and open-source developers with access to the model, allowing them to identify and patch vulnerabilities within their own codebases before malicious parties can leverage similar AI tools. The list of partners includes major industry players such as Amazon Web Services, Apple, Microsoft, and Nvidia, among others.
Autonomous Hacking and the Erosion of Defense-in-Depth
The danger posed by Mythos stems from its ability to operate autonomously. Researchers used Anthropic’s coding agent, Claude Code, to prompt the model to scan specific codebases. The AI then formulated hypotheses about potential bugs and validated them without human intervention. This represents a significant shift from previous models: while its predecessor, Opus 4.6, succeeded in attacking a Firefox JavaScript engine only twice in testing, Mythos achieved success 181 times.
This efficiency threatens traditional defense-in-depth
strategies. Because these models can iterate through tedious tasks at scale, security measures that rely primarily on friction—rather than hard technical barriers—may become ineffective. Anthropic noted that the model is capable of achieving full control flow hijack on fully patched targets, a tier 5 severity rating on their internal scale.
Vulnerabilities in Agentic Web Browsers
While Mythos represents a high-level threat to infrastructure, research from the University of Washington highlights immediate risks for everyday users of agentic AI browsers. These browsers, designed to perform tasks like planning travel or managing calendars, often require browser-level access. The UW team found that four of seven popular agentic browsers created pathways to bypass the same-origin policy,
a fundamental security protocol introduced in 1995 that prevents websites from accessing each other’s data.

In a proof-of-concept attack, researchers successfully demonstrated how a malicious website could steal sensitive information—such as emails or bank account details—from another tab.
- ChatGPT Atlas
- Chrome with Gemini
- Claude for Chrome
- Perplexity Comet
The researchers warn that these browser agents are not yet ready for public use. Even for savvy users, granting an agent access to a browser containing active credentials poses a significant risk.
The Race to Secure Infrastructure
Anthropic has identified thousands of high-severity vulnerabilities
through its testing, including issues in the Linux kernel and the FFmpeg library. However, the volume of these findings is immense; the company reported that fewer than 1% of the discovered vulnerabilities have been fully addressed.
Looking ahead, the industry expects a surge in similar AI-driven security tools. Axios reported that OpenAI is finalizing a model with capabilities comparable to Mythos, which will also be subject to a restricted, limited release. As these models evolve, the focus for both Anthropic and its project partners remains on proactive defense, with the goal of ensuring that the benefits of AI-accelerated security patches reach the broader software ecosystem before the technology is adopted by hostile actors.
Related reading
Discover more from Archyworldys
Subscribe to get the latest posts sent to your email.