Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity

Browser Security in the Age of Mythos: How AI Is Driving a Surge in Browser Risk Exposure

By Lionel Litty
Laptop in darkness
Hostaphoto via Unsplash
August 4, 2026

Large language models trained on coding tasks have become remarkably adept at finding security issues. Effective enough that Anthropic made the decision to restrict access to its latest model, Mythos. But between software vendors that have access to Mythos and the advances made by other models, it was broadly expected that we would see a large number of security vulnerabilities being found in the near future. 

That future arrived faster than most expected. The patch tsunami is here, and browsers are absorbing the worst of it. This was also expected, given that browsers are the most exposed attack surface and that browser vendors have been at the forefront of vulnerability research.

Vulnerability Discovery Is Exploding

In the span of just over a month, Google released a steady stream of Chrome updates fixing more than 800 security issues: 33 on June 16, 27 on June 11, 74 on June 8, 429 on June 2, 151 on May 27, 16 on May 19, 79 on May 12. For its part, Mozilla fixed 22 security issues found in Firefox in February and then fixed a whopping 271 security issues at the end of April. The issues in Firefox were found by successive versions of Anthropic models: Opus 4.6 in February, Mythos Preview in April. Google has not publicly confirmed exactly how the Chrome vulnerabilities were found, but it is almost certain that LLMs were involved.

What makes this moment feel so different is the tempo. Both the pace and the number of vulnerabilities given a critical severity rating is unprecedented. In the case of Chrome, this has resulted in 7 separate updates in 6 weeks, with each update fixing at least one critical issue, something that would previously rarely happen even twice in 6 weeks.

Beyond Discovery: Exploitation and Evasion

This influx of security fixes is creating risk for people sitting behind browsers because the same models driving discovery have become increasingly capable at the next step: exploitation. The conversation around Mythos and other frontier models has often been focused on their ability to find vulnerabilities, including a 27-year old bug in OpenBSD. While this is impressive, just as important is how much the coding models can help in writing exploits. Turning a vulnerability into an exploit that can reliably compromise a target is far from trivial. 

Mostly, security researchers stop at proof-of-concepts that can crash the browser. This is enough to convince a software engineer that there is a memory safety issue that could lead to an exploit. This leaves significant work that used to require time and specialized skills to weaponize a vulnerability. LLMs accelerate this timeline and lower the barrier to entry. Tasks that used to require deep knowledge can now be assisted and accelerated by the same class of models that are discovering the flaw.

Faster exploitation is not the only way LLMs are shifting the balance. A recent report from the Google Threat Intelligence Group highlights that frontier models are also adept at defensive evasion. Attackers have now started using models to mutate their attack payloads. Security experts have long known that signature based approaches were relatively easy to defeat for a moderately skilled attacker, but this is one more area where the barrier to entry is being lowered.

Rethinking Browser Security for an AI-Driven Threat Landscape

This points to a new reality where there is no time to deploy patches and where band-aid solutions in the form of signature-based attack detections cannot be relied on. Security leaders need approaches that fundamentally address the risks inherent in browsing complex, untrusted websites. 

For browser vendors, this for example means moving to memory safe language to implement browsers, work that is already under way. For everyone else, it means moving the browser attack surface off endpoints and continuing to focus on security fundamentals, such as following the principle of least privilege. This implication shifts away from relying on detection and response to reducing the impact of compromise when they inevitably occur. 

Moving the attack surface off the endpoint means that when a user visits a malicious site, the attack executes in an environment that disappears when the session ends. Nothing reaches the endpoint. Nothing persists. The model found the vulnerability, the attacker wrote the exploit (possibly with the help of the model), and the exploit ran inside a container that no longer exists. In that model, the goal isn’t to eliminate every attack path, but to make successful attacks have far less of an impact.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security risk vulnerability vulnerability assessment vulnerability management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Lionel litty headshot

Lionel Litty is CISO at Menlo Security. Image courtesy of Litty

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Glasses in front of coding on screen

The Good Hackers Security Leaders Can’t Afford to Ignore

Coding

6 Data Breaches to Know About (June 2026)

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • generative AI

    Balancing data privacy and security in the age of AI-powered defenses

    See More
  • Return of the Phone Phreakers: Business Communications Security in the Age of IP

    See More
  • Risk Management, Insider Threats and Security Leaders in the Age of COVID-19

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • Physical Layer Security in Wireless Communications

See More Products

Events

View AllSubmit An Event
  • April 15, 2026

    How AI is Closing the Decision Gap in Leading GSOCs

    ON DEMAND: Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing