Live data from Hacker News

CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

support.apple.com

51–60 of 124 posts

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#51

I wonder how well Apple has deployed these tools internally for security research. Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found by Google. Same period last year was 19 vulnerabilities. They've also become more transparent recently, disclosing vulnerabilities found internally, not just externally (which Apple still doesn't appear to do). From the outside, it's hard to tell if Apple has…

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

You wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it.

Typo, or I am just misreading?

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#52

Earlier quoted context omitted.

My thinking was in a historical context, and for their desktop OS's. I know they've been pretty on top of things with iPhones, and MacOS has become a lot better, but for the longest time MacOS was pretty lacking, coasting very much on promoting how much PCs have viruses and macs didn't, which was a marketshare thing more than a security thing. I don't think they got ASLR until later than pretty much everyone else, fo…

Agree that pre Apple Silicon, macOS didn't get much focus. Fair point historically.

That's a really strange claim given AS was a refinement of a technology other manufacturers have yet to surpass in the ten years since the T1 chip came out.

To this day nobody else ties their SMC, biometric auth, and HSM together as tightly and well as the T1 did. AS was further advancement of that.

Furthermore, Apple protects users against the legal changes that have allowed law enforcement to physically force someone to provide biometric credentials. By default MS just provides biometric auth to make it easier to log in to your system.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#53

when multiple independent parties are simultaneously tripping over different holes in the same kernel, that's not bad luck, that's a systemic attack surface problem

Which gets even better by still using C.

Large majority of CVEs in the update are related to memory corruption, out of bounds and use after free.

Naturally the logic and wrong permissions ones would happen regardless of the language.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#54

Earlier quoted context omitted.

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

[flagged]

Person with an internal viewpoint gives their perspective and you decide the best response was to bite their head off. Wonderful.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#55

Earlier quoted context omitted.

More like: There will be a budget for tokens to be spent on security audits. 1000 different companies will be pitching your CTO their proprietary vulnerability scanning harness as the most cost effective.

So what already happens, but worse?

It's just another tool in the belt. Someone will say that's cheaper than rewriting in safe rust or whatever. (Apple must have a bunch of 1980s code written to 1980s standards. But that is their moneymaker.)

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#56

Earlier quoted context omitted.

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

You wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it. Typo, or I am just misreading?

[dead]

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#57

Earlier quoted context omitted.

They were not "coasting" on anything. Everything about OS X has always been designed to protect users from the stuff Apple hasn't caught yet, because they know they can't always catch it first - and Apple has led the pack in nearly every major OS security feature of the last 25 years. That includes "don't give the user root, and ask the user for their password before doing dangerous things" - four years before Linux…

Didn’t Microsoft pioneer the privilege escalation prompts in Vista in 2007? It was a joke at the time how little things would hijack the entire screen to allow seemingly mundane things. I didn’t ever use Vista personally or professionally, but macOS has become pretty bad with basically the same model.

MacOS X prompted users for their passwords in 2001.

Microsoft's implementation was (twenty years later still is) a joke because it prompted users to hit enter or click a button.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#58

Earlier quoted context omitted.

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

You wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it. Typo, or I am just misreading?

The heavily ironic implication is that they're under NDA, so they can't attest to it, while more or less attesting it. Senator, I cannot confirm or deny that we definitely do this.

This could also be an unofficial-official way for Apple to "leak" that yes, they do this--which is on brand for how Apple handles "rumors" etc.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#59
post #34

Oh hey, this is our work! We helped Anthropic analyze and report this bug. For the record, this bug has nothing to do with our recent MIE attack [1] [2], which exploited two different kernel bugs. Our bugs are not fixed yet. [1] https://blog.calif.io/p/first-public-kernel-memory-corruptio... [2] https://news.ycombinator.com/item?id=48139219

[deleted]

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#60
post #34

Oh hey, this is our work! We helped Anthropic analyze and report this bug. For the record, this bug has nothing to do with our recent MIE attack [1] [2], which exploited two different kernel bugs. Our bugs are not fixed yet. [1] https://blog.calif.io/p/first-public-kernel-memory-corruptio... [2] https://news.ycombinator.com/item?id=48139219

hijacking the top comment

vulnerabilities have already been fixed, and the system update was pushed 2026/05/11 †

> This document describes the security content of macOS Tahoe 26.5.

think: this is what we included with the tahoe 26.5 update 2 weeks ago

thanks ZPrimed (https://news.ycombinator.com/item?id=48273889)

https://support.apple.com/en-us/122868

Post reply on HN