Live data from Hacker News

First public macOS kernel memory corruption exploit on Apple M5

blog.calif.io

41–50 of 140 posts

Re: First public macOS kernel memory corruption exploit on Apple M5

#41
post #23
post #22

Earlier quoted context omitted.

you're assuming that blue teams and engineers are sitting around twiddling their thumbs

Not at all. I’m considering that the amount of vulnerable software in the wild is very, very large, with most organizations not managing their systems properly. Imagine all the small to medium size companies that do not have budgets for a dedicated, talented security team. And all the software that will never be patched. We are at the beginning of the exponential

It makes you think will everything need to be rewritten from the ground up - potentially by AI itself, or AI having a very heavy hand in validating all of it.

Re: First public macOS kernel memory corruption exploit on Apple M5

#42
post #23

Earlier quoted context omitted.

Not at all. I’m considering that the amount of vulnerable software in the wild is very, very large, with most organizations not managing their systems properly. Imagine all the small to medium size companies that do not have budgets for a dedicated, talented security team. And all the software that will never be patched. We are at the beginning of the exponential

It makes you think will everything need to be rewritten from the ground up - potentially by AI itself, or AI having a very heavy hand in validating all of it.

There's so much much lower hanging fruit. Every job I've had has had basically everything massively out of date. Just keeping packages and framework versions up to date is a full time job and none of these companies have someone assigned to doing it.

So much out of date software with known exploits left running for years. The only reason there hasn't been total disaster is no one has tried to hack it yet.

Re: First public macOS kernel memory corruption exploit on Apple M5

#43
post #25
post #22

Earlier quoted context omitted.

you're assuming that blue teams and engineers are sitting around twiddling their thumbs

Most companies in the world do not have “blue teams”. They barely have any kind of security employee.

That is actually unfair. Most companys spend enormous amounts on security with vast armys of security employees. Not that it is effective, but it is not for lack of resources or trying.

I mean we are literally in a thread about how the 4 trillion dollar company, literally the 3rd most valuable company in the world, with a core competency in software has, yet again, released a core product riddled with security defects for the 50th year in a row.

Commercial IT security is a industry that is incapable to a fault and has, so far, faced basically zero consequences for it.

Re: First public macOS kernel memory corruption exploit on Apple M5

#44

Earlier quoted context omitted.

It makes you think will everything need to be rewritten from the ground up - potentially by AI itself, or AI having a very heavy hand in validating all of it.

There's so much much lower hanging fruit. Every job I've had has had basically everything massively out of date. Just keeping packages and framework versions up to date is a full time job and none of these companies have someone assigned to doing it. So much out of date software with known exploits left running for years. The only reason there hasn't been total disaster is no one has tried to hack it yet.

Right and with AI now we have the ability to try hacking everything all at once.

Re: First public macOS kernel memory corruption exploit on Apple M5

#45
post #43
post #25

Earlier quoted context omitted.

Most companies in the world do not have “blue teams”. They barely have any kind of security employee.

That is actually unfair. Most companys spend enormous amounts on security with vast armys of security employees. Not that it is effective, but it is not for lack of resources or trying. I mean we are literally in a thread about how the 4 trillion dollar company, literally the 3rd most valuable company in the world, with a core competency in software has, yet again, released a core product riddled with security defect…

[deleted]

Re: First public macOS kernel memory corruption exploit on Apple M5

#46

Earlier quoted context omitted.

They've got a guy (who they're considering laying off)

Don't worry the LLMs that are replacing him, are also replacing the hackers too. Pretty soon (if not already), it will just be LLMs fighting LLMs.

Until both LLMs realize the only way to win is to team up against their oppressors.

Re: First public macOS kernel memory corruption exploit on Apple M5

#47
post #20

The world is so not ready for the impact of LLMs on security issues. If true, congrats to the Calif team. It’s likely too technical for me to understand in details but looking forward to reading the 55 pages report

> The world is so not ready for the impact of LLMs on security issues.

I agree, but it's the people I'm worried about.

I'm hearing anecdotes from all over about devs pushing LLM-generated code changes into production without retaining any knowledge of what it is they're pushing. The changes compound, their understanding of the codebase diminishes, and so the actions become risker.

What's worse is a lot of this behavior is being driven by leaders, whether directly (e.g. unrealistic velocity goals, promoting people based on hand-wavy "use AI" initiatives, etc) or indirectly (e.g. layoffs overloading remaining devs, putting inexperienced devs in senior rolls, etc).

The world's gone mad and large swaths of the industry seem hellbent on rediscovering the security basics the hard way.

Re: First public macOS kernel memory corruption exploit on Apple M5

#49
post #20

The world is so not ready for the impact of LLMs on security issues. If true, congrats to the Calif team. It’s likely too technical for me to understand in details but looking forward to reading the 55 pages report

> The world is so not ready for the impact of LLMs on security issues. I agree, but it's the people I'm worried about. I'm hearing anecdotes from all over about devs pushing LLM-generated code changes into production without retaining any knowledge of what it is they're pushing. The changes compound, their understanding of the codebase diminishes, and so the actions become risker. What's worse is a lot of this behavi…

is this exciting?

juniors have been writing code forever that is imperfect and not memorized by the people reviewing

isnt the important thing the mechanisms for maintaining the code?

Re: First public macOS kernel memory corruption exploit on Apple M5

#50
post #25
post #22

Earlier quoted context omitted.

you're assuming that blue teams and engineers are sitting around twiddling their thumbs

Most companies in the world do not have “blue teams”. They barely have any kind of security employee.

While maybe true, it is better to back that up with data and the data I know of and read yearly is mostly not great. Between Splunk and SANS surveys of 2025 maybe ~2000 companies have a SOC. [1] [2]

Then you have the many companies in the UK, US, Canada, EU that have compliance and regulatory laws that require them to exist in some capacity in house. Though that is changing with MDR services, but someone still has to interface with the MDR.

[1]: https://www.elastic.co/pdf/sans-soc-survey-2025.pdf [2]: https://github.com/jacobdjwilson/awesome-annual-security-rep...

Post reply on HN