A consumer-grade AI cooked up a Chrome exploit for $2,283.
A researcher asked Claude Opus 4.6, the same model accessible to anyone for a monthly subscription, to create the code to exploit a fixed Chrome bug. The bill: $2,283, 20 hours, and Discord opening your Mac’s calculator without your permission. That’s the security researchers’ convention for saying: if we can do that, we can do anything.
What’s happening
Starting point: a bug in Chrome, fixed and made public. In the security world, “fixed publicly” means the exact nature of the problem is now accessible to everyone, in Google’s official database. Not a secret, a known flaw, documented, with the fix readable by anyone.
Mohan Pedhapati, a security researcher at Hacktron, submitted this bug to Claude Opus 4.6 with a simple question: build me the code to exploit it.
After 20 hours and 1,765 exchanges with the model: a program that runs in Discord and opens your Mac’s calculator. No data theft, no destruction. The calculator. That’s the security researchers’ tradition: when they want to prove a vulnerability lets someone run a program on your machine without your permission, they prove it by opening calc. Harmless, but eloquent: if someone can open the calculator without asking, they can just as well run anything else.
Total bill: $2,283. The model that counts calories in your recipes can also, with guidance and patience, write a browser exploit.
Why it’s important for you
“In Discord” isn’t incidental. Discord, Slack, Teams, Notion, Spotify, VS Code: none of these apps are native. They’re web apps disguised, built on Chrome’s engine. Result: when Chrome fixes a bug, these apps keep running on the old version until they update on their own. Discord was still running on a vulnerable Chrome version when Pedhapati published his exploit. The official fix had been available for weeks.
The implications are wide. Before this study, turning a fixed bug into a functional exploit took years of specialized expertise. Now, it takes $2,283 and someone who knows how to ask the right questions to a model. The list of fixed Chrome bugs is public. The list of apps lagging in patches is too.
It’s exactly what Schneier described as inevitable about Mythos, and it’s happening, not with a military model.
What you need to do
→ Immediate: update Chrome, Safari, Firefox, Edge on your Mac tonight. The latest Chrome version fixes the exact bug used in the study, but the point is there will be others like it. Otherwise, do what I do: uninstall Chrome and switch to Safari. But that’s another conversation.
→ This week: review the “web disguised” apps on your Mac. Discord, Slack, Teams, Notion, Spotify, VS Code, 1Password desktop if you still use it. For each, check preferences to ensure automatic updates are on and you’re running the latest version. An app that’s abandoned or rarely updated becomes a prime target.
→ To watch: the reaction of Discord, Slack, and others to the update frequency of their internal engine. The arrival of commercial services packaging this kind of experimentation, today a researcher in a lab, tomorrow a product on the darknet. The first real campaigns using AI-assisted browser exploits against poorly maintained apps. If it happens, that’ll be another conversation.
Sources
- Security Affairs - April 20, 2026
- Hacktron Study - Pedhapati - April 20, 2026
- Schneier on Mythos - April 13, 2026 (context)