跳到正文
原文
@kimmonismus· @kimmonismus · X·· 2026-05-16精选AI 评分67
AI 导读

三位研究者用 Anthropic 的 Mythos 构建出可用的 macOS 内核漏洞利用,绕过了 Apple M5 的内存完整性强制(MIE)机制。该漏洞 4 月 25 日发现、5 月 1 日做出可用利用,团队没有破解 MIE 而是绕过它,属于无指针操作的数据型攻击,从非特权用户直达 root,并前往 Apple Park 当面提交报告。55 页技术报告将在 Apple 完成修复后发布。

推荐理由

三位研究者用 AI 模型做出绕过 Apple M5 MIE 的内核漏洞利用,读者可看到 AI 辅助安全研究的一条具体路径。

正文

Three researchers used Anthropic's Mythos to build a working macOS kernel exploit that bypasses Apple's M5 Memory Integrity Enforcement, a security system Apple spent five years and billions of dollars building.

Bug found April 25. Working exploit May 1. Walked into Apple Park to deliver the report in person.

MIE was the flagship security feature of the M5 and A19, designed to kill the entire memory corruption bug class. According to Apple's own research, it disrupted every known public exploit chain against modern iOS.

Calif didn't break MIE. They walked around it. Data-only attack, no pointer manipulation, standard syscalls from an unprivileged user to root.

The 55-page technical report drops after Apple patches.

This is the story of the year in cybersecurity.

引用International Cyber Digest (@IntCyberDigest)@IntCyberDigest
Video of exploit in action. Source: blog.calif.io/p/first-public… Video
在 X 查看被引用的帖子

来源:@kimmonismus · x.com