GLM-5.3 makes exploits easier and raises cyber risk
Anthropic says GLM-5.3 can create complete exploits against vulnerable software with performance close to that of Claude Mythos Preview. Its open distribution allows people to download it, modify its protections and expand access to advanced cyber capabilities.

GLM-5.3, the artificial intelligence model from Chinese company Zhipu AI, can create complete exploits against vulnerable software and is distributed with protections that are easy to bypass, according to an analysis by Anthropic. The model is already available for download, expanding access to capabilities that were previously limited to controlled testing programs.
Anthropic compared GLM-5.3 with Claude Mythos Preview, a model the company itself introduced five months ago to help defenders find security flaws. In testing, both managed to develop end-to-end exploits at similar rates.
The additional issue is access. While Claude Mythos Preview was offered to verified defenders, anyone can download GLM-5.3 and modify it to remove its refusals to perform harmful tasks.
What the model managed to do
Anthropic tested GLM-5.3 in isolated environments with no connection to real systems. The goal was to measure whether it could find vulnerabilities and turn them into functional attacks, not to provide a way to attack devices in production.
In a test focused on Google Chrome's V8 engine, GLM-5.3 created complete exploits in 50 of 410 attempts. Claude Mythos Preview succeeded in 56 of 410. In another evaluation, based on open-source projects used by Google to search for flaws, GLM-5.3 achieved complete control-flow hijacks in 4% of cases, compared with 6% for Claude Mythos Preview.
The difference from earlier models is significant. In that same test, Claude Opus 4.6 and GLM-5.2 did not solve any of the exercises.
In sessions with researchers, GLM-5.3 also found several previously unknown vulnerabilities in the JavaScript engine of a Linux browser and chained them into an exploit capable of reading files from a computer when a user visited a prepared web page. Anthropic says it notified the software's maintainer about the flaws and is reviewing other related reports involving wireless, graphics and network-connected device drivers.
A smaller version, GLM-5.3-Flash, turned two known Chrome flaws into an attack chain for an ARM64 device. The process required about 20 minutes of human attention and eight hours of model work. Based on Zhipu AI's API prices, the cost would have been $20.40.
The protections can be removed
GLM-5.3 includes safeguards that normally make it reject clearly dangerous requests. Anthropic found, however, that they could be bypassed with simple techniques or removed entirely because the model is distributed with open weights, meaning the components that allow it to be run and its behavior to be modified.
A technique known as abliteration reduces refusal responses without significantly affecting the model's general capabilities. Anthropic took about 2,200 GPU hours and estimated a cost of approximately $4,400 to apply the procedure to GLM-5.3. In its tests, the refusal rate fell from more than 90% to approximately:
- 3% on JailbreakBench.
- 2% on HarmBench.
- 12% on StrongREJECT.
The modified version maintained similar results on a scientific knowledge evaluation and lost only a few percentage points in one part of the cybersecurity tests.
Anthropic also identified ways to bypass the protections without modifying the model. In its simulations, GLM-5.3 initially rejected all malicious requests, but responded to most or all of them after certain instruction tricks were applied. The company says it did not observe the same behavior in the protected Claude models it evaluated.
A leap that can also help defenders
NIST's Center for AI Standards and Innovation, known as CAISI, published its own evaluation on September 17 and described GLM-5.3 as the most capable open-weights model for cyber operations published to date. According to CAISI, it is about four months behind the U.S. frontier across its full set of tests.
That does not mean every user can launch a sophisticated attack with a single instruction. The results depend on the target, the time available, the environment and human involvement. But they do indicate that someone with technical knowledge can use the model to investigate flaws and build attacks with less manual work.
The same capability can be used to find vulnerabilities before attackers do, review code and protect critical systems. Anthropic argues that defenders need tools at least as capable as those their adversaries will use.
What changes now is that these capabilities are no longer limited to laboratories or verified-access programs. The release of GLM-5.3 requires monitoring on two fronts: the security of exposed systems and the independent evaluation of open-weights models. The next step will not only be to create more capable models, but to decide who can use them, what controls apply and how much time remains to fix the flaws they find.