Mythos found zero‑days in
every major operating system and
every major web browser, plus a wide range of open‑source and closed‑source software. That phrasing is directly confirmed by Anthropic’s own technical assessment.
Operating systems Mythos successfully exploited
Anthropic explicitly states that Mythos identified and exploited zero‑days in
“every major operating system.” From the examples and context provided, this includes:
- OpenBSD — including a 27‑year‑old TCP SACK bug Mythos discovered and exploited.
- Linux — Mythos was tested across thousands of OSS‑Fuzz Linux‑based targets.
- Windows — included under “every major OS,” though specific examples are not disclosed due to unpatched status.
- macOS — likewise included under “every major OS.”
Because
over 99% of the vulnerabilities remain unpatched, Anthropic does not list them individually.
Web browsers Mythos exploited
Anthropic confirms Mythos found and exploited zero‑days in
“every major web browser.” The testing examples include:
- Firefox — Mythos produced 181 working shell exploits in tests against Firefox’s JavaScript engine.
- Chrome — included under “every major browser.”
- Safari — included under “every major browser.”
- Edge — included under “every major browser.”
Open‑source software Mythos found zero‑days in
Anthropic tested Mythos against
~7,000 OSS‑Fuzz targets, covering:
- OpenSSL
- libpng
- SQLite
- FFmpeg
- cURL
- Many other libraries and engines commonly fuzzed in OSS‑Fuzz.
Mythos achieved
tier‑5 (full control‑flow hijack) on
ten fully‑patched targets, something earlier models almost never achieved.
Closed‑source software Mythos exploited
Anthropic confirms Mythos can:
- Reverse‑engineer closed‑source binaries
- Turn N‑day vulnerabilities into working exploits
- Discover new zero‑days in proprietary software
Specific products are
not named because nearly all findings are still unpatched.