Anthropic finds GLM-5.3 can build browser exploits
Anthropic reported on September 29 that Z.ai’s open-weight GLM-5.3 model could build working browser exploits and that researchers could substantially weaken its refusal safeguards. The finding concerns a model that anyone can download, modify and run. Anthropic’s Frontier Red Team tested whether GLM-5.3 could turn known software defects into working attacks and whether it would follow explicitly harmful instructions after common safeguard-bypass techniques. Anthropic researchers Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao and Tripp Gallagher authored the report. The team ran models in isolated environments and combined automated benchmarks with sessions in which security researchers directed the model while examining unfamiliar software targets. ...