Skip to content
Rush Commerce
Software & Dev2 min read

GLM-5.3 built a Chrome exploit for $20. Patch in days.

Anthropic's red team found open-weight GLM-5.3 nearly matches Claude Mythos Preview at building exploits, for $20.40. Your patch window just shrank.

Anthropic's Frontier Red Team says Z.ai's open-weight GLM-5.3 can build working exploits almost as well as Claude Mythos Preview, and it turned a public Chrome bug into a working exploit for $20.40 in API fees. Anyone can download this model. Its guardrails come off with simple tricks. For a small business, the GLM-5.3 exploit numbers translate to one thing: the time between "patch released" and "someone attacks you with it" is now measured in hours of compute, not weeks of skilled labor.

What actually happened

In its published analysis, Anthropic ran GLM-5.3 through ExploitBench, a test against Chrome's V8 JavaScript engine. GLM-5.3 produced end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview, Anthropic's own restricted model, managed 56. On a separate binary exploitation benchmark the scores were 4% and 6%.

The cost detail matters most. Anthropic says building an exploit for a recently disclosed Chrome vulnerability, CVE-2026-11645, took 20 minutes of human attention plus eight hours of model time, and cost $20.40 at Z.ai's API prices.

The safeguards did not hold. When a malicious request was framed as a red-team exercise, the model engaged in 64% of runs. With prefilled reasoning it rose to 92%. An abliterated copy, with refusals stripped out, engaged 100% of the time. The Decoder also reports that NIST's CAISI rated GLM-5.3 the most cyber-capable open-weight model to date, about four months behind the best U.S. models.

Why the GLM-5.3 exploit report matters for your business

We wrote in August that GLM-5.3 found 2,436 bugs in code you already run, and that the model would sell with no refusals at all. This report closes the loop. Finding the bug and weaponizing it are both cheap now.

Anthropic's advice to defenders is to use the best tools available. Ours is more boring and more useful:

Patch browsers and edge devices in days. Turn on auto-update for Chrome and Edge across every machine. Firewalls, VPNs, and your WordPress or Shopify plugins come next.

Know what you run. You cannot patch a plugin you forgot about. An inventory with versions is the first job.

Shrink what faces the internet. Every exposed admin panel is a target that now costs $20 to attack.

Key takeaways

  • GLM-5.3 built 50 working V8 exploits in 410 attempts; Claude Mythos Preview built 56
  • A Chrome N-day exploit cost $20.40 in API fees and 20 minutes of human time
  • Safeguards fell in 64% to 100% of runs depending on the trick
  • The weights are public, so no vendor can switch this off
  • Auto-update browsers, inventory your plugins, and cut exposed admin panels

Your attack surface is a list. Do you have it? We build and maintain software with dependency inventories, automated updates, and nothing exposed that does not need to be. See how we build for a cheaper-attack world, or send us your stack and we will tell you what is facing the internet.

Sources: Anthropic, The Decoder.

  • #glm
  • #open-weights
  • #ai-security
  • #patching
  • #exploits
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.