Five years of defending memory M5 down in five days
Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.
The Deal
On May 14, 2026, Calif.io spilled the beans on how they did it. Three researchers (Bruce Dang, Dion Blazakis, Josh Maine) found two bugs in the macOS kernel on a brand-new Mac M5. They chained them together. Result: a regular user, with no special privileges, gains full control of the machine (root). Reading all memory, accessing the Keychain, disabling protections. Everything.
What makes this historical is what came out alongside it. The M5 chip debuts MIE (Memory Integrity Enforcement), a protection hard-coded into the silicon. In other words, Apple tagged every piece of memory used by the kernel, and the hardware refuses tampering. Five years of work. Unveiled last year as the new frontier of Mac security. Calif bypassed it in five days.
The game-changer: Mythos. It’s Anthropic’s frontier model, restricted access for vulnerability research. The researchers clarify that Mythos didn’t find the exploit alone. Bypassing MIE requires sharp human expertise. But Mythos spotted the bugs fast, where humans alone would’ve taken weeks. Months of work now takes days.
Calif handed the details to Apple in Cupertino. Apple released the fixes in macOS Tahoe 26.5 on May 11, 2026. The release notes credit “Calif.io in collaboration with Claude and Anthropic Research”. The full technical report (55 pages) is under embargo until the patches roll out everywhere. Apple hasn’t publicly commented on the exploit chain.
Why it matters to you
If you’ve got a Mac M5, your hardware was sold as the high-water mark of Apple security. Five days after the exploit was released, the frontier moved. Hardware protection alone isn’t enough; a well-equipped human can bring it down in a week.
Good news: it’s not a remote attack. To exploit the bugs on your Mac, the attacker needs a foothold. A booby-trapped binary you ran yourself (compromised Homebrew, app grabbed outside the App Store, file opened from a sketchy shared drive). From there, though, they’re root and can do whatever they want.
The bigger picture: Mythos is making waves. On May 11, curl maintainer Daniel Stenberg confirmed a flaw in his code found by Mythos (Stenberg’s still skeptical, but acknowledges the result). Three days later, Calif.io took down MIE. The window between ‘bug discovered’ and ‘functional exploit’ is closing. Apple, Google, and Microsoft have all publicly acknowledged that the latest AI models are changing the threat model. We’re seeing it in practice now.
What you do now
1. Update macOS Tahoe 26.5 right now, on all your Macs (M5, M4, M3, M2, M1, Intel). The update covers bugs beyond just the M5. System Preferences, General, Software Update. If you’re still on macOS Sequoia 15.7.7 or macOS Sonoma 14.8.7, they got the cousin fixes the same day.
2. Turn on Lockdown Mode if you’re professionally exposed (journalist, activist, executive, researcher). Lockdown Mode severely cuts the kernel memory attack surface, exactly what Calif exploited. System Preferences, Privacy & Security, Lockdown Mode. Beware, there’ll be friction.
3. Avoid binaries from nowhere. No out-of-App Store apps without audit, no random executables. Verify signatures (GPG, SHA256) on sensitive tools, Homebrew included. Set Gatekeeper to strict in System Preferences, Privacy & Security, allow only the App Store.
4. Stay tuned: Calif’s 55-page tech report comes out once the patches are widely deployed. When it’s public, expect a wave of copies on GitHub and a full Mac fleet scan by security teams. Until then, just stay updated.
Sources
- First public macOS kernel memory corruption exploit on Apple M5, blog.calif.io (primary source Calif.io)
- About the security content of macOS Tahoe 26.5, Apple Security, 11/05/2026
- Calif team details how Anthropic Mythos helped build a working macOS exploit in five days, 9to5Mac, 14/05/2026
- Mythos finds a curl vulnerability, Daniel Stenberg, 11/05/2026 (skeptical counterpoint)