Summary
A security research team called Calif has achieved the first public privilege escalation exploit on Apple’s M5 silicon, bypassing the chip’s Memory Integrity Enforcement (MIE) — a hardware-assisted memory safety system designed specifically to prevent this class of attack. The researchers gained full root access on macOS 26.4.1 running on bare-metal M5 hardware.
What makes this particularly notable: the team used Anthropic’s Claude Mythos Preview AI model to identify and chain two kernel vulnerabilities together, developing the full exploit in just five days. The exploit works by chaining standard system calls to escalate from an unprivileged user to root, completely sidestepping Apple’s latest hardware defenses.
Apple has been notified and is reportedly working on a fix. The exploit currently requires local access, limiting its immediate threat surface — but it fundamentally demonstrates that M5’s vaunted memory protections are not impenetrable.
Sources
- Tom’s Hardware — Apple M5 First Privilege Escalation Exploit
- Calif Security Blog — First Public Kernel Memory Corruption on M5
- Cyber Insider — First macOS Kernel Exploit on M5 Chips
Commentary
This is a watershed moment at the intersection of AI and offensive security. The M5’s Memory Integrity Enforcement was supposed to be Apple’s definitive answer to memory corruption exploits — a hardware-level defense that couldn’t be circumvented by software tricks alone. Five days with an AI assistant proved that wrong.
The speed is what should alarm everyone. What previously took elite security researchers weeks or months of manual reverse engineering and fuzzing was accomplished in under a week with AI augmentation. Claude Mythos didn’t just find a bug — it helped chain two kernel vulnerabilities into a working privilege escalation. This is the future of vulnerability research, and it’s already here. Defenders need to internalize that their patch windows just got dramatically shorter.
