First public macOS kernel memory corruption exploit on Apple M5

378 points - yesterday at 6:25 PM

Source

Comments

andai today at 8:33 AM
So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name?

I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

yellow_lead today at 9:16 AM
Did Mythos have access to Apple's source code?

> Apple spent five years building it. Probably billions of dollars too.

This seems higher than I'd expect.

fguerraz today at 11:04 AM
This is incredibly light in details, no verifiable claim as far as I can tell.

(I’m sure they’re not lying, but we’re not learning anything here)

yieldcrv yesterday at 8:28 PM
from what they demonstrated, this seems to only be a $100,000 exploit in Apple's bug bounty platform, but if they package it right, it could be a $1.5 million exploit

They simply have to show it against a beta version of MacOS, and frame it as unauthorized access, and maybe from locked mode if possible

dgellow yesterday at 9:26 PM
The world is so not ready for the impact of LLMs on security issues. If true, congrats to the Calif team. It’s likely too technical for me to understand in details but looking forward to reading the 55 pages report
vsgherzi yesterday at 6:32 PM
unfortunately a little light on the details. I'm very curious how the bug survived through MTE
jp0001 today at 3:22 AM
LLMs are going to produce amazing Rube Goldberg style vulnerabilities for years to come. It's already starting, this instance isn't the case, but it's happening.
isodev today at 4:41 AM
I’m surprised Apple is still not dogfooding their allegedly safe language Swift. Or was the whole exercise of Swift 6 mostly marketing
nicktaobo today at 4:45 AM
[dead]
AgentME yesterday at 7:40 PM
[flagged]
tkel today at 12:11 AM
[flagged]
commandersaki yesterday at 8:48 PM
I bought the M5 specifically cause of MIE. Now I feel dumb.
bredren yesterday at 7:41 PM
Did the article get edited? There is not much description of the field trip.