Security researchers use Anthropic Mythos to expose macOS vulnerabilities on Apple M5 chips

Reviewed byNidhi Govil

11 Sources

Share

Security firm Calif used Anthropic Mythos to create a privilege escalation exploit for macOS, bypassing Apple's Memory Integrity Enforcement on M5 silicon in just five days. The discovery marks the first public macOS kernel memory corruption exploit on M5 chips and highlights AI's growing role in cybersecurity research, though experts say fears of AI-enabled hacking may be overstated.

Security Researchers Breach Apple's M5 Protection Using Anthropic Mythos

A Palo Alto-based security research company called Calif has successfully created a privilege escalation exploit for macOS using Anthropic Mythos, marking a significant development in AI cybersecurity. The researchers worked with Anthropic's Claude Mythos Preview to identify macOS vulnerabilities and develop an exploit that bypasses Memory Integrity Enforcement (MIE), a security feature Apple introduced on M5 and A19 chips

1

. What makes this discovery particularly notable is the speed: building the code that exploited two MacOS bugs took just five days, compared to the half-decade Apple spent developing MIE technology

1

.

Source: Digit

Source: Digit

The exploit represents the first public macOS kernel memory corruption exploit on M5 silicon, allowing attackers to run a command as a standard user and gain root access to the machine

2

. While Macs are rarely used as servers, limiting practical impact, the vulnerability remains concerning as it's relatively easy to trick users into running malicious code, and with full system control, the exploit becomes hard to detect and remove

2

.

How AI-Assisted Security Research Uncovered the Vulnerability

Calif disclosed the vulnerability to Apple in advance through an in-person meeting at Apple Park in Cupertino, delivering a 55-page report detailing their findings

5

. The researchers tested their code on an Apple M5 machine running macOS 26.4.1, successfully bypassing the hardware-level security enforced by MIE

2

. Calif's chief executive, Thai Dong, emphasized that while the AI model for vulnerability discovery played a crucial role, the attack "couldn't have been pulled off by Mythos alone and leveraged the very human cybersecurity expertise of some of Calif's hackers"

5

.

Source: MacRumors

Source: MacRumors

The discovery was published as part of Calif's Month of AI-Discovered Bugs series, highlighting the expanding role of AI tools in uncovering software vulnerabilities

2

. Apple has responded seriously to the findings, stating that "Security is our top priority, and we take reports of potential vulnerabilities very seriously"

4

. Calif plans to release full technical details only after Apple fixes the vulnerabilities and attack path

4

.

Mythos Preview and Project Glasswing's Broader Impact

Anthropic uses Claude Mythos Preview for Project Glasswing, an initiative launched in April to prevent AI cyberattacks with AI

4

. Participants include major technology companies such as Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks

4

. Mozilla previously announced finding and patching 271 vulnerabilities in Firefox with help from Anthropic Mythos

4

.

The company warned at Mythos's launch in April that the AI model had uncovered thousands of software vulnerabilities across every major operating system and browser

3

. This prompted governments in multiple countries to huddle with banks assessing risks, and by early May the White House was weighing rules to control how new models are released after safety testing

3

.

Industry Experts Say Unfettered Hacking Fears May Be Overstated

Despite initial alarm, cybersecurity experts suggest concerns about unfettered hacking enabled by Anthropic Mythos may be overblown

3

. Isaac Evans, founder and CEO of software security firm Semgrep, noted "a really big communication gap between practitioners and policymakers," explaining that while the model represents "a real technical advance," the response "is not substantiated by what we actually know about how those capabilities will translate in the field"

3

.

One person with extensive vulnerability research experience using early access to Mythos told Reuters: "We've been able to use AI to find more bugs than we know what to do with for months if not years"

3

. The challenge isn't finding vulnerabilities but validating, prioritizing, and fixing them without breaking systems. Anthony Grieco, senior vice president and chief security officer at Cisco, highlighted that Mythos helps experienced practitioners scan vast amounts of code faster and lower false positive rates, allowing defenders to focus on pressing cyber risks

3

.

Source: Reuters

Source: Reuters

The broader AI cybersecurity landscape is evolving rapidly, with OpenAI recently introducing its own initiative called Daybreak, using various AI models including specialized security agent Codex, in response to Project Glasswing

4

. This development shows how AI is fundamentally changing the race between attackers and defenders, though human cybersecurity experts remain essential to maximize these tools' effectiveness.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved