Just in:

Claude exploit test rattles browser security

Anthropic’s Claude Opus has been thrust into a fresh security debate after researcher Mohan Pedhapati said he used the model to help build a working V8 exploit chain that achieved code execution against an outdated Chromium build bundled with Discord. Pedhapati, CTO of Hacktron and known online as s1r1us, said the exercise ran over about a week, consumed 2.3 billion tokens, cost $2,283 in API fees and ended with a proof-of-concept that launched Calculator on an Apple Silicon Mac.

The claim is serious, but narrower than a plain reading of “Chrome exploit” suggests. Pedhapati’s write-up describes the target as Chrome for Testing 138 on ARM64 macOS and says Discord Desktop was using Chrome 138 while current upstream Chrome had already moved to version 147. Google’s Chrome release notes show version 147.0.7727.55 and.56 were promoted to the stable channel on April 7, while the National Vulnerability Database says CVE-2026-5873, an out-of-bounds read and write flaw in V8, affected Chrome versions prior to that build and could allow arbitrary code execution inside the sandbox through a crafted HTML page.

That chronology matters because Pedhapati did not present the model as an autonomous cyber weapon that could break a fully patched mainstream browser on its own. His account says the model needed repeated steering, multiple sessions and human judgement to get past dead ends. He wrote that he selected a bug he believed was workable, used patch information to help the model construct an out-of-bounds primitive, then pointed it at a disclosed sandbox-bypass issue from the Chromium tracker to complete the chain. He also noted that an XSS on discord. com would still be needed to deliver such a payload against Discord itself.

Even with those caveats, the episode lands awkwardly for anyone arguing that offensive AI remains mostly theoretical outside controlled demonstrations. Pedhapati’s larger point is that exploit development for complex software has been constrained by scarce human expertise, and that models can now compress parts of that work into something faster and cheaper. His target choice also revived an older concern around Electron-style applications that ship with their own Chromium versions and can lag well behind upstream security fixes, leaving known browser flaws exposed after patches are public.

Anthropic’s own published research already points in the same direction, though with more restraint. On March 6, the company said Claude Opus 4.6 had found 22 Firefox vulnerabilities over two weeks and that it managed to turn a bug into an exploit only twice, despite being given hundreds of attempts. Anthropic stressed that those exploits worked only in a testing environment with some modern browser protections intentionally removed and said the model was not yet writing full-chain exploits that could escape the browser sandbox in the kind of real-world manner that would cause the most harm.

Yet Anthropic has also been warning that the broader trajectory is moving fast. On April 7 it launched Project Glasswing with partners including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, saying its unreleased Mythos Preview model had already found thousands of high-severity vulnerabilities across major operating systems and browsers. Reuters reported that Anthropic paired that effort with up to $100 million in usage credits and $4 million in donations for open-source security work, underscoring how aggressively the industry is trying to tilt such capability towards defence before wider diffusion makes that harder.

Regulators and large institutions are now treating that risk as more than a laboratory concern. Reuters reported on April 17 that Anthropic was in discussions with the European Commission about its cyber-security models and the obligations to assess and mitigate any associated risks. Separate Reuters reporting the same week said Barclays chief executive C. S. Venkatakrishnan had described Mythos as a serious threat and warned that stronger successors would follow. Another Reuters report on Anthropic’s cyber push cited a survey by IBM and Palo Alto Networks in which 67% of 1,000 executives said they had been targeted by AI attacks within the past year.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Fire hits Starlink station supporting Ukraine connectivity // Amari Koh Samui and OZO Chaweng Samui invite active travellers to fill their trip with more of the experiences they love // MIHAS Reaffirms Malaysia’s Pivotal Role in the Growing Global Halal Economy // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // Long-lived Linux kernel flaw permits root container escape // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services // Fake Firefox add-on targets Google sessions for takeover // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // Thailand Unveils First National Semiconductor Strategy, Targets $80 Billion in Investment by 2050 // Adobe opens Premiere to Android with free 4K editing // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Pope Leo centres Paris visit on eastern Christians // UNGA 81: India Positions Itself As A Bridge Across A Fragmenting World // Belt and Road Summit in Hong Kong welcomes over 6,200 global leaders to explore new business opportunities // UAE flags $141bn water funding gap amid AI demand // Kweichow Zhenjiu Partners with CDF Cruise to Host Exclusive Tasting Event Aboard “Adora Magic City” // Binzhou Aerospace Exploration Center, New Landmark for Science, Cultural Tourism // Bhoi (Fear) Yet To Be Out, And Bhorsa (Assurance) Not Yet In // Saudi Arabia anchors $90bn regional hotel pipeline // China deploys 26th internet satellite group from Hainan //