GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
← Back to feed

Mythos Chained 2 Unknown macOS Kernel Bugs Into a Working Exploit in 5 Days — Apple Is Investigating

Security researchers at Calif, a Palo Alto-based firm, used early access to Anthropic’s Mythos in April to discover two previously unknown macOS kernel vulnerabilities and chain them into a working privilege escalation exploit. The finding, first reported by The Wall Street Journal and corroborated by 9to5Mac, represents the most concrete demonstration yet of Mythos operating at genuine zero-day capability.

The exploit does not rely on a single flaw. Mythos connected two separate bugs and supplied additional exploitation techniques that allowed the researchers to corrupt memory, bypass Apple’s memory integrity protections, and gain access to protected kernel regions that normal applications cannot reach. Apple has confirmed it is investigating.

What Makes This Significant

Privilege escalation exploits at the kernel level have historically required months of manual analysis. The macOS kernel — which controls memory, processes, permissions, and hardware access — is defended by multiple overlapping mitigations designed to make memory bugs extremely hard to convert into reliable control. Mythos changed the economics of that search.

Vulnerability research is structurally a dead-end problem: analysts form hypotheses, inspect code behavior, reason across low-level constraints, and discard most paths before finding one that holds. Where human researchers might spend weeks exploring a single candidate path, Mythos can traverse a much larger search space per unit of time.

The Calif team’s five-day timeline from engagement to working exploit is the specific data point that will alarm security teams across the industry.

The Broader Pattern

This is not Mythos’s first high-stakes security result. Mozilla researchers used Mythos to find 271 Firefox vulnerabilities with near-zero false positives. OpenAI’s GPT-5.4 earned a dedicated cybersecurity variant after its own security research results. The pattern across both labs is consistent: frontier models with extended reasoning significantly accelerate the hypothesis-generation and constraint-reasoning phases that previously bottlenecked offensive security research.

The structural implication is that Mythos can now function as a force multiplier for any research team — including adversarial ones — targeting any sufficiently large and complex codebase.

Apple’s Exposure

The macOS kernel is not a niche target. It underpins every Mac sold — consumer, enterprise, and government. Privilege escalation at kernel level, chained with initial access via a separate exploit, provides the foundation for everything from credential theft to persistent implant installation to full disk access.

Apple has not disclosed a timeline for patches. The responsible disclosure process is underway. Until patches ship, the vulnerability details remain non-public, but the existence of a working exploit is now confirmed.

The Policy Overhang

The White House blocked Anthropic’s earlier push to expand Mythos access from 50 to 120 organizations. Japan’s FSA convened a risk meeting with major banks over Mythos’s financial sector implications. The macOS kernel finding adds a third concrete data point to the argument that Mythos-class models represent a qualitatively different threat surface than their predecessors — and that the current access controls, while restrictive, are not preventing the capability from being demonstrated.