I don't buy it. A lot of stuff this finds is also just simply wrong, benignly reported as true, despite upper/lower layers in the code burying the possibility of a vulnerability actually being exploited. It's a performance/security trade-off too, it always has been. Additional checks and other measures do in fact need to be performed for security purposes.
Great marketing as always, but the rose-tinted view many have seems vicariously misplaced.
I guess you could look at https://red.anthropic.com/2026/cvd/ to see exactly what was discovered.
Specially when this has been OAI/Anthropic's MO for years at this point.
In the article they describe how all the vulns are actually exploitable end to end and >1000 have been independently verified as critical.
These aren't unreachable vulns.