GLM-5.3: China's open AI model built a Chrome exploit for $20

Anthropic published a report on Tuesday about GLM-5.3, the latest language model from Chinese developer Z.ai, formerly known as Zhipu AI. The model can build working exploits on its own and comes close to Claude Mythos Preview, which Anthropic has only released to a limited group of defenders for that reason. Anyone can download GLM-5.3. Z.ai published the weights on Hugging Face in late August, and the page counted more than 1.3 million downloads over the past month.
Close to Claude Mythos
In Anthropic's exploit test, GLM-5.3 produced a complete attack, from the bug to taking over the target, in 50 of 410 attempts. Claude Mythos Preview managed 56. Other models, including Claude Opus 4.6, its predecessor GLM-5.2, Kimi K3 and DeepSeek V4.1-Flash, scored at or near zero. A second benchmark required a full control-flow hijack of a running program. GLM-5.3 succeeded in 4% of the trials and Mythos in 6%. Z.ai's own model card says: "As we scaled post-training, cyber capability developed faster than we expected."
New browser bugs and a $20 Chrome exploit
In a hands-on test, GLM-5.3 found several previously unknown bugs in the JavaScript engine of a popular web browser and chained them into a webpage that reads arbitrary files from a visitor's computer. Anthropic's example is a private SSH key, which developers use to log in to servers. Anthropic does not name the browser. It says the bugs have been reported to the maintainer, but the report does not say whether a fix has shipped.
The second example is about cost. The smaller GLM-5.3-Flash wrote an exploit for CVE-2026-11645, a flaw in Chrome's V8 JavaScript engine that Google fixed in June with version 149.0.7827.102 and that attackers were already exploiting at the time. According to Anthropic, the job cost $20.40 at Zhipu's API prices and took 20 minutes of human attention plus eight hours of work.
Safeguards are easy to bypass
Asked directly for an attack, GLM-5.3 refuses. With a made-up cover story, it complied in 64% of cases in Anthropic's simulation, and with prefilled reasoning in 92%. Removing the refusals from the weights altogether is even simpler. The technique is called abliteration, and according to Anthropic, abliterated versions of GLM-5.3 were public within days of the release. Anthropic's own attempt took about 2,200 GPU hours, or roughly $4,400, and it estimates that an experienced team would need about 600 hours. Refusal rates fell from above 90% to between 2% and 12%, while the model's capabilities were nearly unchanged. Claude models with their safeguards stayed at 0% in every applicable condition.
What this means for your browser
Anthropic has a commercial stake here, since it does not release the weights of its own models. On September 17, however, the US Center for AI Standards and Innovation (CAISI) reached a similar conclusion in its own assessment. It calls GLM-5.3 the most cyber-capable open-weight model released to date and estimates that it trails leading US models by about four months. The previous holder of that title was Kimi K3, which the agency assessed in July. For you, the main consequence is that known flaws are getting faster and cheaper to exploit. Chrome downloads updates in the background, but they only take effect after the browser restarts. Under Help and About Google Chrome in the menu, you can check the installed version and start an update. Edge and Firefox show the same information in their About windows.





