Anthropics Mythos is already finding security flaws in Apple software
AI Breakthrough: How Claude Mythos Found a Major macOS Security Flaw
Imagine an Artificial Intelligence (AI) so incredibly skilled at spotting security weaknesses that its creators decided not to release it to everyone. This is the story of Anthropic's Claude Mythos. It's an AI model designed to be an expert in finding bugs, and because of its advanced capabilities, the company chose not to make it publicly available. Instead, access was granted only to a select group of security experts and large organizations.
First Look at Mythos's Power
Now, we're starting to see just how powerful Mythos truly is. Currently, it's available as "Claude Mythos Preview" to special partners, including major companies like Apple. A recent report from The Wall Street Journal brought to light a significant discovery: security researchers from a company in Palo Alto called Calif used Mythos to uncover a serious flaw in Apple's macOS operating system.
Uncovering a Critical macOS Vulnerability
In a detailed blog post shared by Calif on Thursday, the researchers described their findings. They called this discovery the "first public macOS kernel memory corruption exploit on Apple M5." In simpler terms, this means they found a way to corrupt a critical part of the operating system's memory on Apple's latest M5 chips. They explained that this vulnerability could allow a regular user, without special permissions, to gain complete control over an Apple device. This is a very serious security risk because it could allow malicious software to take over a computer.
How Mythos Helped Find the Flaw
Calif's blog post went on to explain that this powerful exploit involved "two vulnerabilities and several techniques." But here's the most important part: Anthropic's Claude Mythos Preview played a crucial role. It helped the Calif team not only find these hidden bugs but also assisted them in developing the methods to exploit them. This shows the incredible capability of Mythos to understand and interact with complex security challenges.
The researchers from Calif were very impressed by Mythos's abilities. They stated, "Mythos Preview is powerful: once it has learned how to attack a class of problems, it generalizes to nearly any problem in that class. Mythos discovered the bugs quickly because they belong to known bug classes." This means Mythos can learn a specific type of security weakness and then apply that knowledge to find similar problems, even in new and complex systems. It doesn't just find one bug; it understands entire categories of vulnerabilities, making it an incredibly efficient security tool.
Is the Flaw Fixed Yet?
It's not entirely clear whether Apple has already patched this specific security flaw. As MacRumors pointed out, Apple's release notes for macOS Tahoe 26.5, which was released recently, do mention a fix for a bug. This bug was reported by Calif in collaboration with Claude and Anthropic Research, and Calif is also mentioned in two other reports about vulnerabilities. This suggests that Apple is aware of and actively working on the issues raised by Calif and Mythos.
However, Calif's own blog post added a bit of mystery, stating that they met with Apple "early this week." This might imply that the fix for this particular vulnerability is still in progress and has not yet been fully released to the public. Calif also mentioned, "Full technical details will be shared after Apple fixes the vulnerabilities and attack path." This means that once Apple secures its systems, Calif plans to release a more in-depth explanation of the flaw and how it was discovered.
Apple's Response
When questioned by the WSJ about the report, an Apple spokesperson provided a standard response: "Security is our top priority, and we take reports of potential vulnerabilities very seriously." This statement highlights Apple's commitment to user security, which is paramount given the critical nature of the flaw discovered by Claude Mythos and Calif.
The Future of AI in Cybersecurity
The discovery of this macOS kernel memory corruption exploit by Claude Mythos is a landmark moment. It demonstrates the immense potential of advanced AI models to significantly impact cybersecurity, both offensively and defensively. While Mythos's capabilities are currently restricted, this incident sparks important conversations about how such powerful AI tools could shape the future of digital security. They could revolutionize how we find and fix bugs, making our systems safer, but also raise questions about their potential misuse if they fall into the wrong hands.
The fact that an AI can not only identify complex vulnerabilities but also assist in developing the methods to exploit them is a testament to the rapid advancements in artificial intelligence. As AI continues to evolve, its role in protecting and potentially compromising digital infrastructure will only grow, making tools like Claude Mythos both incredibly valuable and critically important to manage responsibly.
from Mashable
-via DynaSage
