Live data from Hacker News

CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

support.apple.com

81–90 of 124 posts

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#81
post #21

This isn't a 26.5 bug, this is a bug fixed in 26.5.

But it's a 26 (Tahoe) bug. Earlier OS versions unaffected

> This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#82

Earlier quoted context omitted.

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

You wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it. Typo, or I am just misreading?

When the CIA representative says "I can neither confirm nor deny" it generally means the atrocities of which the agency has been accused did, in fact, take place.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#83

Earlier quoted context omitted.

They were not "coasting" on anything. Everything about OS X has always been designed to protect users from the stuff Apple hasn't caught yet, because they know they can't always catch it first - and Apple has led the pack in nearly every major OS security feature of the last 25 years. That includes "don't give the user root, and ask the user for their password before doing dangerous things" - four years before Linux…

> They were not "coasting" on anything. Yeah, they were. Virus writers were not targeting them as a platform because why develop for 10% marketshare when you can target 90% for free. It just wasn't worth it to target as a platform. So there was some level of protection due to lack of interest in distributed attacks, but the OS had very little protection against targeted attacks. > Apple has led the pack in nearly eve…

> What an absurd claim. Apple trails behind

Recently there was an Anki vulnerability that gave any website access to any local files. On Windows or Linux this would be deadly. On macOS, Anki can't access my desktop or documents or Chrome storage or password manager storage. I think Apple's been smart about which security features it prioritizes.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#84
post #82

Earlier quoted context omitted.

You wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it. Typo, or I am just misreading?

When the CIA representative says "I can neither confirm nor deny" it generally means the atrocities of which the agency has been accused did, in fact, take place.

When I worked in the civil service we were trained to use that phrase to any query, no matter how innocuous (unless we had permission to give more info).

You may think that not issuing a categorical denial is suspicious, but generally speaking you cannot infer any information from that response. If it was only used when really bad things might have happened, maybe you could infer more.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#85

Earlier quoted context omitted.

What's your thinking on this? From my perspective Apple security go pretty hard. They have a strong track record of being able to ship architectural mitigations like PACs / MIE / Exclaves first. I guess because Apple control the stack from silicon to userspace.

My thinking was in a historical context, and for their desktop OS's. I know they've been pretty on top of things with iPhones, and MacOS has become a lot better, but for the longest time MacOS was pretty lacking, coasting very much on promoting how much PCs have viruses and macs didn't, which was a marketshare thing more than a security thing. I don't think they got ASLR until later than pretty much everyone else, fo…

I am PC, I am Mac campaign is from 2006, quite long time ago.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#86

Earlier quoted context omitted.

Didn’t Microsoft pioneer the privilege escalation prompts in Vista in 2007? It was a joke at the time how little things would hijack the entire screen to allow seemingly mundane things. I didn’t ever use Vista personally or professionally, but macOS has become pretty bad with basically the same model.

MacOS X prompted users for their passwords in 2001. Microsoft's implementation was (twenty years later still is) a joke because it prompted users to hit enter or click a button.

Only if you configure it like that, you can make it ask for a password, and on more recent versions of Windows 11, optionally, a single use token.

Ironically Apple just recently added the same simpified approach.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#87
post #6

Where all of this is going? Will there be a dedicated servers running coding agents that iterate throught codebases for each company to find vulnerabilities 24/7?

Yes, this is quite similar to proper configured CI/CD pipelines, which unfortunely are still a minority across the industry.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#88

I wonder how well Apple has deployed these tools internally for security research. Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found by Google. Same period last year was 19 vulnerabilities. They've also become more transparent recently, disclosing vulnerabilities found internally, not just externally (which Apple still doesn't appear to do). From the outside, it's hard to tell if Apple has…

I am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s…

> there’s no benefit to talk about it

That there's no benefit to talking with the public is something that only Apple could believe.

Openness and honesty create trust. Secrecy creates distrust.

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#89
post #77
post #47

Earlier quoted context omitted.

Then why didn't they?

I think the real point is they didn't - until it became a "marketing" thing for another company who did it for them. A lot of these issues would be highlighted by "legacy" (pre-AI) analysis tools. The issue is that they weren't being run.

Why not? We're talking about vulnerabilities with real market value here. If it was just a tool run, why weren't the tools run?

Isn't the simpler explanation that they weren't just a tool run?

Re: CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

#90
post #89
post #77

Earlier quoted context omitted.

I think the real point is they didn't - until it became a "marketing" thing for another company who did it for them. A lot of these issues would be highlighted by "legacy" (pre-AI) analysis tools. The issue is that they weren't being run.

Why not? We're talking about vulnerabilities with real market value here. If it was just a tool run, why weren't the tools run? Isn't the simpler explanation that they weren't just a tool run?

The tools are expensive. One of the major players in the market have really expensive licensing fees. Then the developers all need to be trained on how to use the tools and understand the results. It’s not something they teach effectively in schools.

Software engineering is still kind of new overall.

Post reply on HN