Full Breakdown
Anthropic’s Claude Mythos AI Assists in Uncovering macOS Kernel Exploit Bypassing Apple Silicon Memory Protections
5/15/2026, 11:52:06 AM
AI-Assisted Kernel Exploit Revealed
Researchers at Calif used Anthropic’s Claude Mythos Preview to combine two macOS bugs into a data-only kernel local-privilege-escalation chain. The exploit bypasses Memory Integrity Enforcement (MIE) on macOS 26.4.1 running on Apple M5 hardware, granting a root shell from an unprivileged account.
Project Glasswing and AI-Driven Vulnerability Research
Anthropic’s Project Glasswing makes Claude Mythos Preview available to companies for security testing. Anthropic engineers have warned the model is “too good at finding security exploits to allow it into the wild.” This macOS case is the first public kernel-memory-corruption attack that defeats Apple’s hardware-assisted MIE protections.
Key Players
- Anthropic – developer of Claude Mythos Preview and Project Glasswing.
- Calif – Palo Alto-based cybersecurity firm that ran the AI-assisted analysis.
- Apple – creator of macOS, M5 silicon, and MIE, currently reviewing the findings.
- Human researchers – provided the expertise needed to turn AI-generated code into a functional exploit.
Technical Details
- Target: macOS 26.4.1 on Apple M5 hardware with MIE enabled.
- Exploit: data-only kernel local-privilege-escalation chain linking two bugs.
- Flow: memory corruption -> root shell.
- Timeline: assembled in roughly five days after bugs were spotted in late April.
- Disclosure: no public code; macOS 26.5 notes a kernel-level fix credited to Calif and Anthropic (WebKit use-after-free fixes also listed).
Official Statements & Responses
Apple’s spokesperson told The Wall Street Journal, “Security is our top priority, and we take reports of potential vulnerabilities very seriously.” Anthropic has not issued a formal comment beyond describing Project Glasswing’s goal of helping companies remediate flaws.
Criticism & Opposition
Anthropic engineers caution that the model’s ability to locate exploits may be misused, emphasizing the danger of AI-generated attack code. Security researchers note human guidance was essential, suggesting AI alone would not yet pose an immediate threat, yet the rapid five-day discovery timeline raises concerns about future attack speed.
Conflicting Reports & Gaps
Apple has not independently confirmed the vulnerabilities or a patch. While macOS 26.5 release notes reference a kernel fix, the specific bugs exploited by Mythos remain undisclosed. Researchers have withheld exploit code pending Apple’s review, leaving technical verification pending.
Verbatim Quotes
- “excited about their discovery.” — Wall Street Journal report
- “Chained attacks The researchers, from a Palo Alto-based research outfit, say that Mythos didn't use a single attack vector in its hack.” — Researchers’ analysis
- “The team said the exploit chain was developed in roughly five days after bugs were identified in late April.” — Research team
- “Anthropic's engineers have warned that it is too good at finding security exploits to allow it into the wild.” — Anthropic internal warning
What’s Next
Apple is reviewing the report and has already referenced a kernel-level fix in the macOS 26.5 update. Anthropic will continue refining Project Glasswing with an emphasis on responsible disclosure, while the security community monitors whether AI-driven vulnerability discovery accelerates further and influences future macOS defenses.
