Apple Mac M5 System Exploited With Anthropic’s Claude Mythos AI, Researchers Claim

by shayaan
OpenClaw Put Apple Back in the AI Game—And Now They Can't Build Macs Fast Enough

In short

  • A security firm claims it has developed a working macOS kernel exploit that targets Apple’s M5 chip and Memory Integrity Enforcement system.
  • The company says a preview version of Anthropic’s Claude Mythos helped AI identify bugs and develop exploits.
  • Apple has not yet publicly responded to the claims.

Apple devices have long been considered among the most difficult consumer systems to hack due to the company’s tightly integrated hardware and software security. Now a security startup claims that a small team of researchers used a preview version of Anthropic’s Claude Mythos to build a working exploit against Apple’s new M5 chip protection in less than a week.

In a Substack message published On Thursday, Vietnam-based Calif said it has developed the first public macOS kernel memory corruption exploit capable of surviving Apple’s new Memory Integrity Enforcement (MIE) protection on M5 hardware. Calif said it shared the findings with Apple at a meeting at the tech giant’s headquarters in California.

“We wanted to report it personally, rather than get buried in the flood of submissions that some unfortunate Pwn2Own participants just experienced,” Calif wrote. “Most respected hackers avoid human interaction where possible, so this physical strategy could give us a slight edge in the eternal race for five minutes of fame and glory on Twitter.”

According to Calif, the “attack path” was discovered accidentally after researchers found the bugs on April 25 and then developed a working exploit on May 1.

The exploit chain targets macOS 26 running on Apple M5 systems. According to the company, the attack starts from an unauthorized local user account and escalates to root access using standard system calls. The exploit reportedly combines two vulnerabilities and additional techniques that target bare-metal M5 hardware with kernel MIE enabled.

See also  Franklin Templeton Expands Blockchain Record-Keeping System Benji to Ethereum Layer-2 Scaler Base

Calif said Mythos Preview helped identify the vulnerabilities and assisted in the development of exploits, but added that human expertise was still needed to bypass Apple’s new MIE protections.

“Part of our motivation was to test what is possible when the best models are combined with experts,” the company wrote. “Launching a kernel memory corruption exploit against the best defense within a week is remarkable and says something powerful about this combination.”

Memory corruption bugs are still one of the most common ways attackers break into operating systems and apps, as they can cause an attacker to crash the program, steal data, or even take control of the program. Apple’s MIE feature uses memory tagging technology to make these attacks much more difficult.

Anthropic released the preview version of Mythos in April after internal testing and external evaluations suggested the model could autonomously identify and exploit software vulnerabilities at a level beyond previous public AI models.

Instead of releasing it publicly, Anthropic restricted access to select tech companies, banks and researchers below it Project Glass Wing initiative. That same month, it was also revealed that the US National Security Agency was using Mythos, despite an ongoing feud between Anthropic and Donald Trump’s administration.

Mozilla later said Mythos identified 271 vulnerabilities in Firefox during internal testing, while the UK AI Security Institute found the model could autonomously complete advanced multi-stage cyber-attack simulations.

Users on Myriad: a prediction market platform operated by Declutterparent company Dastan – don’t believe a full release of Claude Mythos is imminent, only a 10.5% chance of a public launch on June 30, at the time of writing.

See also  Fake Mac Clipboard App Delivers New Password-Stealing Malware

Calif called the Apple M5 exploit “a glimpse of things to come.”

“Apple built MIE in a world before Mythos Preview,” Calif wrote. “We are about to learn how the best mitigation technology on Earth will hold up during the first AI bugmageddon.”

Daily debriefing Newsletter

Start every day with today’s top news stories, plus original articles, a podcast, videos and more.

Source link

You may also like

Latest News

Copyright © Sovereign Wealth Signals