Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool

Anthropic recently announced Project Glasswing, an initiative that enables tech companies like Apple to use its new frontier AI model Claude Mythos Preview to find security vulnerabilities across operating systems and web browsers.

macOS Tahoe and iPhone
The Wall Street Journal today reported that researchers at cybersecurity firm Calif used Claude Mythos Preview to uncover a new macOS security vulnerability last month. Specifically, they used the model to write code that links together two macOS bugs in a way that resulted in what is known as a privilege escalation exploit.

The security researchers said the exploit would not have been possible with Mythos alone, as it still required their human expertise on top, but it nevertheless proves that AI can assist with discovering software vulnerabilities.

Apple said it was reviewing Calif's report to validate the findings.

"Security is our top priority, and we take reports of potential vulnerabilities very seriously," an Apple spokesperson told The Wall Street Journal.

It is unclear if Apple has already patched the exploit. Apple's security notes for the macOS 26.5 update released this week mention a fix for a kernel-level vulnerability, and it credits Calif and Anthropic for discovering it. Yet, the report said that Calif only met with Apple this week and suggested that a fix was still coming.

We have reached out to Apple for comment.

Related Roundup: macOS Tahoe
Related Forum: macOS Tahoe

Popular Stories

CarPlay Liquid Glass Light

Anthropic's Claude Comes to CarPlay

Friday September 4, 2026 1:43 pm PDT by
Anthropic added CarPlay integration to the Claude iOS app, which means Claude users can talk to Claude through their in-car infotainment systems. Apple added support for third-party chatbots in CarPlay in iOS 26.4. Chatbot apps with CarPlay integration need to add support for a voice control screen, use Apple's designated CarPlay template, and get an entitlement from Apple. Claude can answer ...
anthopic claude

Anthropic Launches Claude Fable 5.1 With Lower Costs and Fewer False Positives

Tuesday September 1, 2026 12:15 pm PDT by
Anthropic today introduced Claude Fable 5.1 and Claude Mythos 5.1, which the company says are the "world's most advanced models for coding and knowledge work." According to Anthropic, Claude Fable 5.1 sets a new standard for coding, knowledge work, and long-running problem-solving tasks. It achieves similar or better results than Fable 5 at low or medium effort, and has much higher...
macos tahoe

Apple Releases macOS Tahoe 26.7 and macOS Sequoia 15.8

Monday September 14, 2026 10:40 am PDT by
Alongside macOS Golden Gate, Apple today released new versions of macOS Tahoe and macOS Sequoia. macOS Tahoe 26.7 and macOS Sequoia 15.8 are available for users with older Macs or those who don't yet want to update to Golden Gate. The updates can be downloaded through the Software Update section of the System Settings app. On Macs eligible to install macOS Golden Gate, users will see both...

Top Rated Comments

18 weeks ago
If researchers can use ai tools to identify vulnerabilities- so can nation state hackers, and likely small time hackers too.
The arms race towards computing Armageddon has just begun.
Score: 13 Votes (Like | Disagree)
turbineseaplane Avatar
18 weeks ago

I love how this went from Ai discovers bugs to Ai can assist in finding bugs.

It’s the theme of the entire Ai industry right now. Over promised and under delivered
Lest we forget about “AI creating bugs”, which I guarantee you is happening.
Score: 6 Votes (Like | Disagree)
k1121j Avatar
18 weeks ago
I love how this went from Ai discovers bugs to Ai can assist in finding bugs.

It’s the theme of the entire Ai industry right now. Over promised and under delivered
Score: 6 Votes (Like | Disagree)
18 weeks ago

If researchers can use ai tools to identify vulnerabilities- so can nation state hackers, and likely small time hackers too.
The arms race towards computing Armageddon has just begun.
You're not wrong in your intuition that this levels the playing-field on finding exploits, but the end result should be the opposite: The more stress testing, the safer the code. And there languages and techniques that fundamentally evaporate entire classes of bugs, and if enough bugs are found in existing solutions it can prompt maintainers to perform such upgrades. It has a hint of evolution to it: The strong and adaptable solutions will survive. It doesn't have to a pretty journey, I'm not claiming it'll be rainbows and unicorns, but directionally not an armageddon.
Score: 5 Votes (Like | Disagree)
18 weeks ago
“The exploit is a data-only kernel local privilege escalation chain targeting macOS 26.4.1 (25E253). It starts from an unprivileged local user, uses only normal system calls, and ends with a root shell.“

So, same thing still applies. Don’t download random files from the internet and open them. I mean, novel that they’re proud to say AI was involved (they wouldn’t have been able to do it without AI), but, like all security researchers, they’re just in it for their 5 minutes of fame. That it’s unable to cause anyone any distress without a attacker having physical access to the machine (OR access to an unwise person with physical access to the machine) is just kinda where we are with computing today. Nothing for them to really raise an alarm about.
Score: 4 Votes (Like | Disagree)
18 weeks ago
I'm going back to pencil and paper.
Score: 4 Votes (Like | Disagree)

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors