All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

How Researchers Bypassed Apple's M5 Memory Integrity Enforcement in Five Days

By

jiveturkey

5d ago· 22 min readenInsight

Summary

A detailed technical analysis of how security researchers (a three-person team with AI assistance) bypassed Apple's new Memory Integrity Enforcement (MIE) security system on the M5 chip in just five days. The article explains MIE's sophisticated design—hardware memory tagging, locked read-only kernel zones, and a privileged monitor—and the two bugs and clever exploit technique used to defeat it. It provides a rundown accessible to technical readers without requiring a PhD, covering implications for both defenders and exploit writers.

Key quotes

· 3 pulled
It's the most serious kernel memory-safety stack any consumer OS has shipped. And it still got bypassed.
A three-person shop with an AI sidekick walked through it in five days, with two bugs and a clever idea.
Here's my rundown of how they achieved it, no PhD required.
Snippet from the RSS feed
How Calif and Anthropic's Mythos cracked Apple's brand-new Memory Integrity Enforcement on the M5 in five days, what the bug actually is, and what defenders and exploit writers should take from it.

You might also wanna read

Apple unveils Memory Integrity Enforcement: Five-year hardware-software effort to enhance memory safety across devices

Apple announces Memory Integrity Enforcement (MIE), a new memory safety protection system developed over five years that combines Apple sili

security.apple.com·8mo ago

Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities

Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs

cybersecuritynews.com·16m ago

wolfCOSE: A Lightweight COSE + CBOR Library for Embedded Systems with PQC and FIPS 140-3 Support

wolfCOSE is a lightweight C library implementing CBOR (RFC 8949) and COSE (RFC 9052/9053) for embedded systems, using wolfSSL as the crypto

github.com·1d ago

Anthropic launches Claude Security beta for codebase vulnerability scanning

Anthropic has released Claude Security, a defensive security tool within Claude Code on the web, from closed preview to beta for Claude Ente

thenewstack.io·1d ago

How LinkedIn's 2012 Breach Exposed the Dangers of Unsalted Password Hashes

This article examines the 2012 LinkedIn breach where attackers cracked millions of passwords using fast, unsalted hashes like MD5 and SHA-1.

hendryadrian.com·1d ago

AI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator

A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This

infosecurity-magazine.com·1d ago