9 ms·
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
- deleted 4mo ago[deleted]
- fosterfriends 4mo agoKernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-28952: Calif.io in collaboration with Claude and Anthropic Research
- Gigachad 4mo agoIt's funny how in the past a server uptime used to be a kind of badge of honor, while now a computer running for more than a week is a massive security risk. I've had to be on top of updating everything constantly lately.
- embedding-shape 4mo agoClaude and Anthropic is mentioned, but not Mythos, I'm guessing this would mean then this was found outside of the whole Mythos thing, or would there be any reason for them not to mention it, if it was involved?
- sigmar 4mo agoIt was Mythos >Our engineers, working together with Mythos Preview, built a working exploit in five days. https://news.ycombinator.com/item?id=48139219 https://news.ycombinator.com/item?id=48139219
- fl1pper 4mo agoWhere all of this is going? Will there be a dedicated servers running coding agents that iterate throught codebases for each company to find vulnerabilities 24/7?
- vessenes 4mo agoYes
- Aurornis 4mo agoMore like: There will be a budget for tokens to be spent on security audits. 1000 different companies will be pitching your CTO their proprietary vulnerability scanning harness as the most cost effective.
- colejohnson66 4mo agoSo what already happens, but worse?
- flomo 4mo agoIt's just another tool in the belt. Someone will say that's cheaper than rewriting in safe rust or whatever. (Apple must have a bunch of 1980s code written to 1980s standards. But that is their moneymaker.)
- jeffbee 4mo agoWhy shouldn't there be such things? We already have fuzzing, and responsible software publishers dedicate 24/7 resources to fuzzing.
- 0123456789ABCDE 4mo agothis has been the reality for while now google has been running ClusterFuzz since ~2012, and naptime was announced in 2024 (https://projectzero.google/2024/06/project-naptime.html https://projectzero.google/2024/06/project-naptime.html). they call it big sleep and codemender now. openai announced aardvark last year, no they call it codex security.
- pjmlp 4mo agoYes, this is quite similar to proper configured CI/CD pipelines, which unfortunely are still a minority across the industry.
- sda2 4mo agoOne more reason to avoid upgrading to Tahoe.
- hedgehog 4mo agoThis was fixed in 26.5 as well as 15.7.7 etc. https://app.opencve.io/cve/CVE-2026-28952 https://app.opencve.io/cve/CVE-2026-28952
- dragonsenseiguy 4mo ago> One more reason to avoid upgrading to Tahoe. Sequoia also has security bugs :) https://support.apple.com/en-us/127116 https://support.apple.com/en-us/127116
- vessenes 4mo agoFor many years my go-to plan has been to stay one point release behind apple's releases, especially the .0 releases -- but, times change. Last night I pushed the button for 26.5, thinking about the Glasswing/Mythos reporting. Seems like staying on bleeding edge is going to be the name of the game. I wonder if this will change general dynamics -- feels like LTS releases could become even more important, at the same time having reduced maintenance costs since you can have some agentic help on backporting.
- deleted 4mo ago[deleted]
- dragonsenseiguy 4mo agoSame! I almost never updated, now I feel like i need to update. Kinda feels like FOMO but for security updates
- samtheprogram 4mo agoSecurity updates still go out for older major releases back 2 versions. You didn’t need to jump to 26 if you weren’t on it.
- baq 4mo agoTell that to my IT department please
- mort96 4mo agoStaying one point release behind is weird isn’t it? I get staying a major release behind, Apple’s x.0 releases are often pretty rough so it might be worth staying on x-1 for a while. But point releases mostly just fix the stuff they broke in the major release.. Would you really upgrade from 18.5 or whatever to 26.0 when Apple releases 26.1?
- Marsymars 4mo agoPoint releases for macOS can be pretty large over the past several years - what often makes sense is waiting a few weeks to upgrade in case there's a .1 patch. e.g. macOS 15.0, 15.1, 15.3, 15.4, 15.6 and 15.7 all had .1 patches within a few weeks of release.
- neuronexmachina 4mo agoCVEs: * https://nvd.nist.gov/vuln/detail/CVE-2026-28952 https://nvd.nist.gov/vuln/detail/CVE-2026-28952 * https://nvd.nist.gov/vuln/detail/CVE-2026-28942 https://nvd.nist.gov/vuln/detail/CVE-2026-28942
- Aurornis 4mo agoMore than 26.5: > The affected releases include iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5. I’ve already seen a lot of people self-congratulating for not updating to Tahoe but this isn’t exclusive to Tahoe.
- dragonsenseiguy 4mo agoAh thanks! I was only looking at Tahoe since my mac had an update and I usually look at the security release notes.
- tom_ 4mo ago> The affected releases include iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5. Where does this quote come from? I can't see it in https://support.apple.com/en-us/127115 https://support.apple.com/en-us/127115, the article link at time of writing. It mentions CVE-2026-28952, but we're forced to guess why. I'd take the reference to mean that this issue is fixed, but I'm just some internet rando, so what the hell do I know? If I do a google search for "CVE-2026-28952", it points me to various pages. Here's one, for example: https://www.cve.org/CVERecord?id=CVE-2026-28952 https://www.cve.org/CVERecord?id=CVE-2026-28952 - which is a bit more explicit, though of course this is not from the horse's mouth: > This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5
- three_burgers 4mo agoCVE-2026-28952 is about an integer overflow due to lack of input validation. I wonder what makes such vulnerability difficult to discover by traditional SAST tools?
- firesteelrain 4mo agoFuzzing, dynamic analysis or DAST might have found it too. Assuming Apple has deployed all of these and have invested in the labor/training on how to properly use them.
- tptacek 4mo agoThen why didn't they?
- kimixa 4mo agoI think the real point is they didn't - until it became a "marketing" thing for another company who did it for them. A lot of these issues would be highlighted by "legacy" (pre-AI) analysis tools. The issue is that they weren't being run.
- tptacek 4mo agoWhy not? We're talking about vulnerabilities with real market value here. If it was just a tool run, why weren't the tools run? Isn't the simpler explanation that they weren't just a tool run?
- firesteelrain 4mo agoThe tools are expensive. One of the major players in the market have really expensive licensing fees. Then the developers all need to be trained on how to use the tools and understand the results. It’s not something they teach effectively in schools. Software engineering is still kind of new overall.
- AntosTools 4mo ago[flagged]
- ZPrimed 4mo agoThis isn't a 26.5 bug, this is a bug fixed in 26.5.
- dragonsenseiguy 4mo agoAh my bad for the wrong wording.
- awestroke 4mo agoBut it's a 26 (Tahoe) bug. Earlier OS versions unaffected
- dwaite 4mo ago> This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5
- concinds 4mo agoI wonder how well Apple has deployed these tools internally for security research. Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found by Google. Same period last year was 19 vulnerabilities. They've also become more transparent recently, disclosing vulnerabilities found internally, not just externally (which Apple still doesn't appear to do). From the outside, it's hard to tell if Apple has deployed this tooling as much as Google.
- JCattheATM 4mo agoI'd guess they haven't even begun to really utilize them. They've never been a terribly security conscious company, despite the marketing.
- xyzzy123 4mo agoWhat's your thinking on this? From my perspective Apple security go pretty hard. They have a strong track record of being able to ship architectural mitigations like PACs / MIE / Exclaves first. I guess because Apple control the stack from silicon to userspace.
- JCattheATM 4mo agoMy thinking was in a historical context, and for their desktop OS's. I know they've been pretty on top of things with iPhones, and MacOS has become a lot better, but for the longest time MacOS was pretty lacking, coasting very much on promoting how much PCs have viruses and macs didn't, which was a marketshare thing more than a security thing. I don't think they got ASLR until later than pretty much everyone else, for example. They've improved a lot, especially their phones, but I'd still never consider them a company that has a really strong focus on security.
- xyzzy123 4mo agoAgree that pre Apple Silicon, macOS didn't get much focus. Fair point historically.
- dragonsenseiguy 4mo agoSidenote but: it's crazy how big this update is. 13 GB is crazy
- jshier 4mo agoUpdate from 26.3 to 26.4 for the Studio Display XDR was 2.4GB. And that's for a variant of iOS designed for screens.
- atonse 4mo agoYeah I’m honestly not sure why macOS updates seem to be so huge. Often gigabytes. Do they actually have thousands of changes, so they basically ship out new versions of almost all system libraries? Or is it that they don’t have good diffing in place? Or is it a BSD thing where you basically ship everyone at once since it’s all sort of “one version” of the base system?
- alwillis 4mo ago> Yeah I’m honestly not sure why macOS updates seem to be so huge. An update to macOS 26.5 contains all the necessary code to update a Mac from 26.0 to 26.5 for both x86_64 and arm64 architectures.
- qsxfthnkp2322 4mo agoIs that an over the air update? Lol.
- atonse 4mo agoBut aren't they able to do incremental builds and separated x64/arm64? They know which OS version is requesting an update, at least the version number part.
- alwillis 4mo ago> But aren't they able to do incremental builds and separated x64/arm64? During the PowerPC to Intel transition, they did stuff like that; perhaps at their current scale, there's reasons why they don't. Supporting both architectures enables a macOS install to boot an Intel Mac or an Apple Silicon Mac, which is useful in a dual-architecture environment. It's easy to check for dual architecture support; just use the file command: $ file /bin/ls /bin/ls: Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit executable x86_64] [arm64e:Mach-O 64-bit executable arm64e] /bin/ls (for architecture x86_64): Mach-O 64-bit executable x86_64 /bin/ls (for architecture arm64e): Mach-O 64-bit executable arm64e
- cryptbe 4mo agoOh hey, this is our work! We helped Anthropic analyze and report this bug. For the record, this bug has nothing to do with our recent MIE attack [1] [2], which exploited two different kernel bugs. Our bugs are not fixed yet. [1] https://blog.calif.io/p/first-public-kernel-memory-corruption https://blog.calif.io/p/first-public-kernel-memory-corruptio... [2] https://news.ycombinator.com/item?id=48139219 https://news.ycombinator.com/item?id=48139219
- deleted 4mo ago[deleted]
- 0123456789ABCDE 4mo agohijacking the top comment vulnerabilities have already been fixed, and the system update was pushed 2026/05/11 † > This document describes the security content of macOS Tahoe 26.5. think: this is what we included with the tahoe 26.5 update 2 weeks ago thanks ZPrimed (https://news.ycombinator.com/item?id=48273889 https://news.ycombinator.com/item?id=48273889) † https://support.apple.com/en-us/122868 https://support.apple.com/en-us/122868
- maximilianburke 4mo agoI haven't been able to update my iPhone in months because it just does not have enough room available to download the update. I just checked now and it needs 13.2 GB free to be able to update to iOS 26.5 (from 26.3). On a 64gb device! It just seems like massive software development malpractice to tie together critical operating system updates with whatever else they've bundled.
- zx8080 4mo agoI thought one just get a new iphone when run out of storage.
- jonhohle 4mo agoYou can do a tethered update and get a local backup at the same time.
- ttkari 4mo agoI have a 32 GB iPad, I think it's the year 2020 model. The OS alone uses 19 GB ("iPadOS" 12.3 GB + "System Data" 6.4 GB) so yeah, not much chance doing any OTA updates on that one with the requirement of 13+ GB free. Maybe some day the fruit company with all their billions will be able to innovate a solution for deploying for example browser fixes so that they can be installed without requiring tens of gigabytes of free storage on the device. Meanwhile, we're stuck using a computer and iTunes for that.
- dyauspitr 4mo agoIt’s insane. It’s always an ordeal. They put so little storage on these phones that 20% of it is for iOS/system already. On top of that requiring 13-15 GB for an update is a huge pain.
- immanuwell 4mo agowhen multiple independent parties are simultaneously tripping over different holes in the same kernel, that's not bad luck, that's a systemic attack surface problem
- pjmlp 4mo agoWhich gets even better by still using C. Large majority of CVEs in the update are related to memory corruption, out of bounds and use after free. Naturally the logic and wrong permissions ones would happen regardless of the language.
- sitkack 4mo agoA strong enough type system can catch permission problems.
- pjmlp 4mo agoThe solution there would be a capabilities based OS, however adoption hasn't been great on that regard.
- sitkack 4mo agoI'd love to see CHERI (for the room) and Wasm take off, no time like the present. https://en.wikipedia.org/wiki/Capability_Hardware_Enhanced_RISC_Instructions https://en.wikipedia.org/wiki/Capability_Hardware_Enhanced_R... https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/ https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/