Anthropic’s Mythos Preview AI demonstrated something that should change how automakers manage vulnerabilities: the ability to chain low-severity bugs into critical attack paths that would never be flagged by traditional scanning. VicOne researchers warn that the July 2026 disclosure window from Project Glasswing is a near-term forcing function for the automotive industry.
The red team findings were concrete. On Linux, Mythos chained two to four low-severity bugs into a local privilege escalation, where each individual flaw would not have triggered high-priority triage. A browser sandbox escape used four chained vulnerabilities for JIT heap spraying and kernel access. FreeBSD was hit with remote code execution via CVE-2026-4747, a 17-year-old NFS vulnerability discovered and exploited entirely by the AI.
Automotive security teams face a direct parallel. Modern vehicles pack dozens of ECUs running Linux, QNX, and Android. A single low-severity Bluetooth flaw is not a crisis. That same flaw chained with weak telematics permissions and a predictable infotainment memory layout becomes a remote takeover path. CVSS scores in isolation do not reflect the risk of a vulnerability that serves as a link in a chain.
VicOne recommends a shift from CVSS-only triage to attack-path prioritization. Under Glasswing, Anthropic committed to disclosing patched vulnerabilities within 90 days, creating a concentrated decision window. The partners cited on Glasswing’s page made clear that these AI capabilities will reach attackers. The question is not whether automakers can patch every bug, but whether they can sever the dangerous chains first.