Calif Cybersecurity Uses Anthropic AI to Breach macOS M5 Security
Calif Cybersecurity researchers used Anthropic PBC's Mythos AI to develop a privilege escalation exploit bypassing Apple Inc.'s Memory Integrity Enforcement on M5 Macs.
Calif Cybersecurity security researchers have developed a privilege escalation exploit that bypasses Apple Inc.'s Memory Integrity Enforcement on macOS, using Anthropic PBC's unreleased Claude Mythos Preview AI model to accelerate the discovery. The chained attack links two minor bugs with several evasion techniques to corrupt kernel memory on Apple's M5 silicon, potentially allowing an attacker to take full control of a Mac computer.
The Palo Alto-based firm discovered the vulnerability while testing an early version of Mythos in April. Calif Cybersecurity researchers hand-delivered a 55-page technical report to Apple Inc.'s headquarters in Cupertino to discuss the findings directly with Apple's security team. Apple Inc. has stated that security remains its top priority and is currently reviewing the data to validate the reported vulnerabilities.
Calif Cybersecurity CEO Thai Duong emphasized that while the AI accelerated the process, the exploit required significant human cybersecurity expertise and was not achieved by Mythos alone. Duong noted that human expertise remained critical due to the novelty of the MIE system. The researchers intend to withhold all technical specifics until Apple Inc. releases the necessary patches.
The exploit highlights the growing intersection of AI and cybersecurity. Anthropic PBC's Mythos model is part of Project Glasswing, an initiative to share AI tools with select partners for defensive security research. The disclosure underscores how advanced AI models can assist in identifying complex software vulnerabilities, even as human oversight remains essential.