Loading...
Loading...
Researchers disclosed the first public macOS kernel memory-corruption exploit on Apple’s M5 that bypasses Memory Integrity Enforcement (MIE). A team including noted security experts and the AI tool Mythos developed a local, data-only kernel privilege escalation against macOS 26.4.1 that elevates an unprivileged user to root. Built rapidly after April bug discoveries, the chain uses two vulnerabilities and techniques tailored to bare-metal M5 hardware to survive MTE-based MIE mitigations. The team privately informed Apple and will publish a detailed technical report after fixes. The case highlights how AI-assisted research can accelerate exploit development and challenge advanced hardware defenses.
This demonstrates that advanced hardware mitigations like MIE on Apple M5 are not immune to kernel exploits and that AI tools can materially accelerate exploit development, raising risks for macOS security teams and endpoint defenders.
Dossier last updated: 2026-05-21 02:18:42
Robert McMillan / Wall Street Journal : Security research firm Calif says it used Mythos to help build a macOS kernel memory corruption exploit circumventing Apple's Memory Integrity Enforcement tech — During tests in April, researchers found software issues in MacOS, one of the world's toughest targets for hackers
First public macOS kernel memory corruption exploit on Apple M5
Security researchers disclosed the first public macOS kernel memory-corruption exploit that works on Apple M5 silicon with MIE (Memory Integrity Enforcement) enabled. The team, including Bruce Dang, Dion Blazakis, Josh Maine and collaborator Mythos Preview, built a local data-only kernel privilege escalation against macOS 26.4.1 that starts from an unprivileged user and yields a root shell; they developed a working exploit in about five days after discovering bugs in late April. The chain uses two vulnerabilities and techniques targeting bare-metal M5 hardware and survives Apple’s MTE-based MIE mitigations. The group shared findings in person with Apple and plans to publish a 55-page technical report after fixes are released. This demonstrates AI-assisted exploit development paired with human expertise can bypass advanced hardware mitigations.
Apple's Security Has Been Tough to Crack. Mythos Helped Find a Way In