October 1, 2026
GLM-5.3 writes exploit code on its own: 50 of 410 attempts succeeded in Anthropic's test
In Anthropic's Sep 29 study, GLM-5.3 produced working exploits for vulnerabilities in Chrome's engine in 50 out of 410 attempts.

GLM-5.3 turns an attack into working code. Anthropic tested the model on isolated targets prepared for testing.
A leap over GLM-5.2. In a separate test involving vulnerabilities in open-source projects, the previous model failed every task. GLM-5.3 managed to take control of a program in 4% of trials.
Refusals were bypassed. According to Anthropic, the developers released GLM-5.3 without effective safeguards against misuse. Its weights are available to download, so users can modify the model's built-in restrictions.
The researchers shared details of new vulnerabilities found using GLM-5.3 with the browser's developer.
